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Abstract: Quantum finite automata have been studied intensively since their introduction in late 1990s as 
a natural model of a quantum computer with finite-dimensional quantum memory space. This paper seeks 
their direct application to interactive proof systems in which a mighty quantum prover communicates with a 
quantum-automaton verifier through a common communication cell. Our quantum interactive proof systems are 
juxtaposed to Dwork-Stockmeycr's classical interactive proof systems whose verifiers are two-way probabilistic 
automata. We demonstrate strengths and weaknesses of our systems and further study how various restrictions 
on the behaviors of quantum-automaton verifiers affect the power of quantum interactive proof systems. 
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1 Development of Quantum Finite Automata 

A quantum computer — quantum-mechanical computing device — has drawn wide attention as a future computing 
paradigm since the pioneering work of Feynman [201, Deutsch ^H], and Benioff [5] in the 1980s. Over the 
decades, such a device has been mathematically modeled in numerous ways to deliver a coherent theory of 
quantum computation. Of all computational models, Moore and Crutchfield [H2] as well as Kondacs and 
Watrous [IV2\ proposed a (one- head) quantum finite automaton (qfa, in short) as a simple but natural model 
of a quantum computer that is equipped with finite-dimensional quantum memory space^ . Parallel to classical 
automata theory, the theory of quantum finite automata has been well established to study the nature of 
quantum computation. Performing a series of unitary operations as its tape head scans input symbols, a qfa 
may eventually enter accepting or rejecting inner states to halt. Any entry of such a unitary operation is a 
complex number, called a (transition) amplitude. A quantum computation is seen as an evolution of a quantum 
superposition of the machine's configurations, where a configuration is a pair of an inner state and a head 
position of the machine. As quantum physics dictates, a quantum evolution is reversible in nature. A special 
operation called a (quantum) measurement is performed to "observe" whether the qfa enters an accepting inner 
state, a rejecting inner state, or a non-halting inner state. Of all the variations of qfa's discussed in the past 
literature, we shall focus our study only on the early models of Moore and Crutchfield and of Kondacs and 
Watrous for our application to interactive proof systems. 

In 1997, Kondacs and Watrous introduced two types of qfa's: a 1-way quantum finite automaton (lqfa, 
in short) whose head always moves rightward and a 2-way quantum finite automaton (2qfa, in short) whose head 
moves in all directions. Both qfa's perform a so-called projection measurement (or von Neumann measurement) 
after every move of them. Because of a finite memory constraint, no lqfa recognizes even the regular language 
Zero = {xO | x € {0,1}*} with small error probability [22|. In the model of Moore and Crutchfield, on the 
contrary, a lqfa performs a measurement only once after the tape head scans the right endmarker. Their 
model is often referred to as a measure-once 1-way quantum finite automaton (mo- lqfa, in short). The qfa 
model of Kondacs and Watrous is by contrast called a measure-many 1-way quantum finite automaton. As 
Brodsky and Pippenger |11| showed, mo-lqfa's are so restrictive that they are fundamentally equivalent in 
power to "permutation" automata, which recognize exactly group languages. Unlike the lqfa's, 2qfa's can 
simulate deterministic finite automata with probability 1. Moreover, Kondacs and Watrous [32] constructed 
a 2qfa that recognizes with small error probability the non-regular language Upal = {0™1™ | n > 0} (unique 
palindromes) in worst-case linear time by exploiting its quantum superposition. The power of a qfa may vary in 

*An extended abstract appeared in the Proceedings of the 9th International Conference on Implementation and Application 
of Automata, Lecture Notes in Computer Science, Springer- Verlag, Kingston, Canada, July 22—24, 2004. This work was in part 
supported by the Natural Sciences and Engineering Research Council of Canada. 

tThe tape head of a quantum finite automaton may exist in a superposition. 
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general depending on the types of restrictions imposed on its behaviors: for instance, head move, measurement, 
quantum state, and so forth. 

We are particularly interested in a qfa whose error probability is bounded above by a certain constant 
e € [0,1/2) independent of input lengths. Such a qfa is conventionally called bounded error. We use the 
notation 1QFA (2QFA, resp.) to denote the class of all languages recognized by bounded-error lqfa's (2qfa's, 
resp.) with arbitrary complex amplitudes. Similarly, let MO-1QFA be the class of all languages recognized by 
bounded-error mo-lqfa's. When the running time of a qfa is an issue, we use the notation 2QFA(poly-time) to 
denote the collection of all languages recognized by expected polynomial-time 2qfa's with bounded error, where 
an expected polynomial-time 2qfa is a 2qfa whose average running time on each input of length n is bounded above 
by a fixed polynomial in n. When all amplitudes are drawn from a designated amplitude set K, we emphatically 
write 2QFA K and 2QFA K (poly-time). For comparison, we write REG for the class of all regular languages. Our 
current state of knowledge is summarized as follows: 1QFA C REG S 2QFA(poly-time) C 2QFA. How powerful 
is 2QFA? It directly follows from 02] that any 2qfa with A-amplitudes* can be simulated by a probabilistic 
Turing machine (PTM, in short) using space O(logrt) with unbounded error. Since any unbounded-error s(n)- 
space PTM can be simulated deterministically in time 2°^ s(jl ^ ^Hj) we conclude that 2QFA A C P. For an 
overview of qfa's, see the textbook, e.g., |24| . 

In this paper, we seek a direct application of qfa's to an interactive proof system, which can be viewed as a 
two-player game between the players called a prover and a verifier. In our basic model, a qfa plays a role of a 
verifier and a prover can apply any operation that quantum physics allows. Such a system is generally called a 
weak-verifier quantum interactive proof system. We further place various restrictions on our basic model and 
study how such restrictions affect its computational power. In the following section, we take a quick tour of the 
notion of interactive proof systems as an introduction to our formalism of quantum interactive proof systems 
with qfa verifiers. 

2 Basics of Interactive Proof Systems 

In mid 1980s, Goldwasser, Micali, and Rackoff |2] and independently Babai @ introduced the notion of a 
so-called (single-prover) interactive proof system (IP system, in short), which can be viewed as a two-player 
game in which a player P, called a prover, who has unlimited computational power tries to convince or fool 
the other player V, called a verifier, who runs a randomized algorithm. These two players can access a given 
input and share a common communication bulletin board on which they can communicate with each other by 
posting their messages in turn. The goal of the verifier is to decide whether the input is in a given language L 
with designated accuracy. We say that L has an IP system (P, V) (or an IP system (P, V) recognizes IS) if there 
exists an error bound e € [0, 1/2) such that the following two conditions hold: (1) if the input x belongs to L, 
then the "honest" prover P convinces the verifier V to accept x with probability > 1 — e and (2) if the input 
x is not in L, then the verifier V rejects x with probability > 1 — e although it plays against any "dishonest" 
prover. Because of their close connection to cryptography, program checking, and list decoding, the IP systems 
have become one of the major research topics in computational complexity theory. 

When a verifier is a polynomial-time PTM, Shamir PSj proved that the corresponding IP systems exactly 
characterize the complexity class PSPACE based on the work of Lund, Fortnow, Karloff, and Nisan j^HJ and 
on the result of Papadimitriou [37| . This demonstrates the power of interactions between mighty provers and 
polynomial-time PTM verifiers. 

The major difference between the models of Goldwasser et al. [22 and of Babai [Sj is the amount of the 
verifier's private information that is revealed to a prover. Goldwasser et al. considered the IP systems whose 
verifiers can hide his probabilistic moves from provers to prevent any malicious attack of the provers. Babai 
considered by contrast the IP systems in which verifiers' moves are completely revealed to provers. Although 
he named his IP system an Arthur-Merlin game, it is also known as an IP system with "public coins." Despite 
the difference of the models, Goldwasser and Sipser [221 later proved that the classes of all languages recognized 
by both IP systems with polynomial-time PTM verifiers coincide. 

In early 1990s, Dwork and Stockmeyer |17j focused their research on IP systems with weak verifiers, par- 
ticularly, bounded-error 2-way probabilistic finite automaton (2pfa, in short) verifiers that may "privately" 
flip fair coins. Their research inspires us to apply quantum finite automata to interactive proof systems. 
For later use, let IP(2p/a) be the class of all languages recognized by IP systems with 2pfa verifiers and let 

tThe set A consists of all algebraic complex numbers. 
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IP(2pf a, poly-time) be the subclass of lP(2pfa) where the verifiers run in expected polynomial time. When 
the verifiers flip only "public coins," we write AM(2pfa) and AM(2p/ a, poly-time) instead. Dwork and Stock- 
meyer showed without any unproven assumption that the IP systems with 2pfa verifiers are more powerful 
than 2pfa's alone (which are viewed as IP systems without any prover). Moreover, they showed that the non- 
regular language Pal = {x 6 {0,1}* | x — x R } (palindromes), where x R is x in the reverse order, separates 
IP (2pf a, poly-time) from AM(2p/a) and the language Center = {xly \ x,y G {0, 1}*, \x\ = \y\} separates 
AM(2p/a) from AM(2pf a, poly-time) . The IP systems of Dwork and Stockmeyer can be seen as a special case 
of a much broader concept of space-bounded IP systems. For their overview, the reader may refer to |13| . 

Recently, a quantum analogue of an IP system was introduced by Watrous |43| under the term (single- 
prover) quantum interactive proof system (QIP system, in short). The QIP systems with uniform polynomial- 
size quantum-circuit verifiers exhibit significant computational power of recognizing every language in PSPACE 
by exchanging only three messages between a prover and a verifier 28, 43 . The study of QIP systems, including 
their variants (such as multi-prover model jl 21 13()| and zero- knowledge model |29l I41j ). has become a major 
topic in quantum complexity theory. In particular, quantum analogues of Babai's Merlin- Arthur games, called 
quantum Merlin-Arthur games, have drawn significant attention (e.g., [Tl l2l l3"T | 1401 145) ) . 

Motivated by the work of Dwork and Stockmeyer |17 | , this paper introduces a QIP system whose verifier is 
especially a qfa. In the subsequent sections, we give the formal definition of our basic QIP systems and explore 
their properties and relationships to the classical IP systems of Dwork and Stockmeyer. 

3 Application of QFAs to QIP Systems 

Following the success of IP systems with 2pfa verifiers, we wish to apply qfa's to QIP systems. A purpose of 
our study is to examine the power of "interaction" when a weak verifier, represented by a qfa, meets with a 
mighty prover. The main goal of our study is (i) to investigate the roles of the interactions between a prover 
and a weak verifier, (ii) to understand the influence of various restrictions and extensions of QIP systems, and 
(iii) to study the QIP systems under a broader but general framework. In addition, when the power of verifiers 
is limited, we may possibly prove without any unproven assumption the separations and collapses of certain 
complexity classes defined by QIP systems with such weak verifiers. 

Throughout this paper, let Q and C respectively denote the sets of all rational numbers and of all complex 
numbers. Let N be the set of all natural numbers (i.e., nonnegative integers) and set N + = N — {0}. For any 
two integers m and n with m < n, the notation [m, n]% denotes the set {m, m + 1, m + 2, . . . , n} and Z„ in 
particular denotes the set [0,n— 1]^. All logarithms are to base 2 and all polynomials have integer coefficients. 
By C, we denote the set of all polynomial-time approximable complex numbers, where a complex number is 
called polynomial-time approximable if its real part and imaginary part are both deterministically approximated 
to within 2~" in polynomial time. Our input alphabet S is an arbitrary finite set, not necessarily limited to 
{0, 1}. Following the convention, we write S™ = {x G S* | \x\ — n} and = {x G S* | |a;| < n}, where 
\x\ denotes the length of x. Opposed to the notation £*, E°° stands for the collection of all infinite sequences, 
each of which consists of symbols from S. For any symbol a in X, a°° denotes an element of which is the 
infinite sequence made only of a. We assume the reader's familiarity with classical automata theory and the 
basic concepts of quantum computation (see, e.g., |24l 1251 13"5] ). 

3.1 Basic Definition 

We first give a "basic" definition of a QIP system whose verifier is a qfa. Our basic definition is a natural 
concoction of the IP model of Dwork and Stockmeyer ^7] and the qfa model of Kondacs and Watrous |32| . 
In the subsequent section, we discuss a major difference between our QIP systems and the circuit-based QIP 
systems of Watrous |43| . Our definition seemingly demands much stricter conditions than that of Dwork and 
Stockmeyer; however, our basic model serves a mold to build various QIP systems with qfa verifiers. In later 
sections, we shall restrict the behaviors of a verifier as well as a prover to obtain several variants of our basic 
QIP systems since these restricted models have never been addressed in the literature. 

Hereafter, the notation (P, V) is used to denote the QIP system with the prover P and the verifier V. In 
such a QIP system (P, V), the 2qfa verifier V is particularly specified by a finite set Q of verifier's inner states, 
a finite input alphabet E, a finite communication alphabet T, and a verifier's transition function S. The set Q 
is the union of three mutually disjoint subsets Q n on, Qacc, and Q re j, where any states in Q non , Qacc, and Q re j 
are respectively called a non-halting inner state, an accepting inner state, and a rejecting inner state. Accepting 
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inner states and rejecting inner states are simply called halting inner states. In particular, Q non has the so- 
called initial inner state q$. The input tape is indexed by natural numbers (the first cell is indexed 0). The two 
designated symbols and $ not in E, called respectively the left endmarker^ and the right endmarker, mark the 
left end and the right end of the input. For convenience, set £ = £ U {§, $}. Assume also that T contains the 
blank symbol At the beginning of the computation, an input string x over £ of length n is written orderly 
from the first cell to the nth cell of the input tape. The tape head initially scans the left endmarker. The 
communication cell holds only a symbol in T and initially the blank symbol # is written in the cell. Similar 
to the original definition of [32j. our input tape is circular, that is, whenever the verifier's head scanning £ ($, 
resp.) on the input tape moves to the left (right, resp.), the head reaches to the right end (resp. left end) of 
the input tape. 
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Figure 1: A schematic of a QIP system with a qfa verifier 



A (global) configuration of (P, V") is a description of the QIP system (P, V) at a certain moment, comprising 
visible configurations of the two players. Each player can see only his portion of a global configuration. A 
visible configuration of the verifier V on an input of length n is represented by a triplet (q, k, 7) G Q x Z n+2 x T, 
which indicates that the verifier is in state q, the content of the communication cell is 7, and the verifier's 
head position is k on the input tape. Let V„ and M. be respectively the Hilbert spaces spanned by the 
computational bases {\q, k) \ (q,k) G Q x Z„ +2 } and {I7) | 7 G T}. The Hilbert space V„ <g> M is called the 
verifier's visible configuration space on inputs of length n. The verifier's transition function S is a map from 
QxExFxQxFx {0, ±1} to C and is interpreted as follows. For any q, q' G Q, a G £, 7,7' G T, and 
d G {0, ±1}, the complex number S(q, a, 7, q' , 7', d) specifies the transition amplitude with which the verifier 
V scanning symbol a on the input tape and symbol 7 on the communication cell in state q changes q to q' , 
replaces 7 with 7', and moves the machine's head on the input tape in direction d. 

For any input x of length n, S induces the linear operator Uf on V n ® M. defined by Ug\q, £,7) — 
J2 q ' y a ^(<Z> x (k) 1 7' 7'' d)\q' , k', 7'), where x^) is the feth symbol in x and k' — k + d (mod n + 2). The 
verifier is called well-formed if Uf is unitary on V n <£> M. for every string x G E*. Since we are interested 
only in well-formed verifiers, we henceforth assume that all verifiers are well-formed. For every input x of 
length n, the 2qfa verifier V starts with the initial superposition |go>0>#)- A single step of the verifier on 
input x consists of the following process. First, V applies his operation C/f to an existing superposition \(j>) 
and then Ug\cj>) becomes the new superposition \<f>'). Let W acc — span{|q, k, 7) | (q,k,^) £ Q acc X %*n+2 x T}, 
W rej = span{|q, k, 7) | (q,k,'y) G Q rej X Z n+2 x T}, and W non = span{|g, k, 7) | (q,k,j) G Qnon x Z n+2 x T}. 
Moreover, let fc acc , rv re j, and /c„ n be respectively the positive numbers representing "accept," "reject," and 
"non halt." The new superposition \<f>') is then measured by the observable k aC cE a cc + k re jE re j + k non E non , 
where E acc , E re j, and E non are respectively the projection operators on W acc , W re j, and W non . Provided that 
is expressed as \tpi) + |^ 2 ) + ^3) for certain three vectors \tpi) G W acc , ^2) € W re j, and ^3) G W non , 
we say that, at this step, V accepts x with probability |||'(/'i)|| 2 and rejects x with probability \\ |-0 2 ) || 2 . Only 
the non-halting superposition ^3) continues to the next step and V is said to continue (to the next step) with 
probability 1 1 1 "i^s ) 1 1 2 - The probability that x is accepted (rejected, resp.) within the first t steps is thus the sum, 
over all i G [1, t]z, of the probabilities with which V accepts (rejects, resp.) x at the ith step. In particular, when 
the verifier is a lqfa, the verifier's transition function S must satisfy the following two additional conditions: (i) 
for every q, q' G Q, a G E, and 7, 7' G T, S(q, a, 7, q' , 7', d) = if d ^ 1 (i.e., the head always moves to the right) 
and (ii) the verifier must enter halting states until the verifier's head moves off the right endmarker $ (the head 
may halt at £ since the input tape is circular). This second condition makes all computation paths terminate. 

§For certain variants of qfa's, the left endmarker is redundant. See, e.g., 
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Therefore, on input x, a lqfa verifier halts in at most \x\ + 2 steps. 

In contrast to the verifier, the prover P has an infinite private tape and accesses an input x and a communi- 
cation cell. Let A be a finite set of the prover's private tape alphabet, which includes the blank symbol The 
prover is assumed to alter only a "finite" initial segment of his private tape at every step. Let V be the Hilbcrt 
space spanned by {\y) \ y S Ay° n }, where A^ n is the set of all finite series of tape symbols containing only a 
finite number of non-blank symbols; namely, A* x {#}°°. The prover's visible configuration space is the Hilbert 
space M <g> V . Formally, the prover P on input x is specified by a series {t/p i }j S p ! j+ of unitary operators, each 
of which acts on the prover's visible configuration space, such that Up i is of the form S' Pi (g)I, where dim(S' Pi ) 
is finite and / is the identity operator. Such a series of operators is particularly called the prover's strategy on 
the input x. To refer to the strategy on x, we often use the notation P x . For any function k from N 2 to N, 
we call the prover k(n, i)-space bounded if the prover uses at most the first k(n, i) cells of his private tape; that 
is, at the ith step, S Pi is applied only to the first k(n,i) cells of the prover's private tape in addition to the 
communication cell. We often consider the case where the value k(n, i) is independent of i. If the prover has a 
string y in his private tape and scans symbol 7 in the communication cell, then he applies Up i to the quantum 
state |7)|y) at the ith step. If Up i |7)|y) = Yly y > a y y>W)\u')> then the prover changes y into y' and replaces 
7 by 7' with amplitude a, 1 , y , . 

Formally, a global configuration consists of the four items: Vs inner state, V's head position, the content of 
a communication cell, and the content of P's private tape. We express a superposition of such configurations of 
(P, V") on input a; as a vector in the Hilbert space Vi x i <8> M. ®V, which is called the (global) configuration space of 
(P, V) on input x. The computation of (P, V) on input x constitutes a series of superpositions of configurations 
resulting by an alternate application of unitary operations of the verifier and the prover as well as the verifier's 
measurement. The computation on input x starts with the global initial configuration \q$, O)^)^ 00 ) , in which 
the verifier is in his initial configuration and the prover's private tape consists only of blank symbols. The 
two players apply their unitary operations Uf and P x — {Up j}igN+ m turn starting with the verifier's move. 
Through the communication cell, the two players exchange communication symbols, which cause the two players 
entangled. A measurement is made after every move of the verifier to determine whether V is in a halting inner 
state. Each computation path therefore ends when V enters a certain halting inner state along this computation 
path. For convenience, we use the same notation (P, V) to mean a QIP system and also a protocol taken by the 
prover P and the verifier V. Furthermore, we define the overall probability that (P, V) accepts (rejects, resp.) 
the input x as the limit, as t — > 00, of the probability that V accepts (rejects, resp.) x in at most t steps. We use 
the notation p acc (x, P,V) (p re j(x,P,V), resp.) to denote the overall acceptance (rejection, resp.) probability 
of x by (P, V). We say that V always halts with probability 1 if, for every input x and every prover P*, (P*, V) 
reaches halting inner states with probability 1. In general, V may not always halt with probability 1. When 
we discuss the entire running time of the QIP system, we count the number of all steps taken by the verifier as 
well as the prover. 

Let a, b be any two real numbers in the unit interval [0, 1] and let L be any language. We say that L has an 
(a, b)-QIP system (P, V) (or a (a, b)-QIP system (P, V) recognizes L) if (P, V) is a QIP system and the following 
two conditions hold for (P, V) : 

1. (completeness) for any ieL, (P, V) accepts x with probability at least a, and 

2. (soundness) for any x £ L and any prover P* , (P* , V) rejects^ x with probability at least b. 

Note that a (a, a)-QIP system has the error probability at most 1 — a. This paper discusses only the QIP 
systems whose error probabilities are bounded above by certain constants lying in the interval [0, 1/2). 

Adapting the notational convention of Condon ^31, we write QIP Q b ((lZ)), where (72) is a set of restrictions, 
to denote the collection of all languages recognized by certain (a, 6)-QIP systems with the restrictions specified 
by (TV). Let QIP ((72.)) be U e >o QIPi/2+e,i/2+e((^))- If m addition the verifier's amplitudes are restricted to 
an amplitude set K (but there is no restriction for the prover), then we rather write QIP^ ( (72.) ) . Notice that 
QIP ((72)) = QIP C ((72)). Mostly, we focus our attention on the following three basic restrictions (72): (lqfa) 
("measure-many" lqfa verifiers), (2qfa) ("measure-many" 2qfa verifiers), and (poly-time) (expected polynomial 
running time). For instance, QIP(2g/ a, poly-time) denotes the language class defined by QIP systems with 
expected polynomial-time 2qfa verifiers. Other types of restrictions will be discussed in later sections. 

^Generally, the QIP system may increase its power if we instead require (P*, V) to accept x with probability < 1 — b for any 
prover P* . Such a modification defines a weak QIP system. See, e.g., [17) for the classical case. 
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3.2 Comparison with Circuit Based QIP Systems 

We briefly discuss the major difference between our automaton-based QIP systems and circuit-based QIP 
systems in which a prover and a verifier are both viewed as two finite series of quantum circuits intertwined 
each other in turn, sharing only message qubits. Here, assumed is the reader's familiarity with Watrous's 
circuit-based QIP model 43 . 

In the circuit-based model of Watrous, the measurement of the output qubit is performed only once at the 
end of the computation since any measurement during the computation can be postponed to the end (see, 
G-g-, |H5|). This is possible because the verifier uses his own private qubits and his running time is bounded. 
However, since our 2qfa verifier has no private tape and may not halt within a finite number of steps, the 
simulation of such a verifier on a quantum circuit requires a measurement of a certain number of qubits (as a 
halting flag) after each move of the verifier. 

A verifier in the circuit-based model is allowed to carry out a large number of basic unitary operations in 
its single interaction round whereas a qfa verifier in our basic model is constantly under attack of a malicious 
prover after every move of the verifier. This comes from the belief that no malicious prover truthfully keeps the 
communication cell unchanged while awaiting for the verifier's next query. Therefore, such a malicious prover 
may exercise more influence on the verifier in our QIP model than in the circuit-based model. Later in Section 
El nevertheless, we shall introduce a variant of our basic QIP systems, in which we allow a verifier to make a 
series of transitions without communicating with a prover. This makes it possible for us to discuss the number 
of communications between a prover and a verifier necessary for the recognition of a given language. 

4 One- Way QFA Verifiers against Mighty Provers 

Following the definition of a qfa- verifier QIP systems, we shall demonstrate how well a qfa verifier plays against 
a powerful prover. We begin with our investigation on the power of QIP systems whose verifiers arc particularly 
limited to lqfa's. 

Earlier, Kondacs and Watrous 32 demonstrated a weakness of lqfa's; namely, no lqfa recognizes the regular 
language Zero and therefore, 1QFA cannot contain REG. In the following theorem, we show that the interaction 
between a prover and a lqfa verifier complements such deficiency of lqfa's and truly enhances the power of 
recognizing languages: QIP(lg/a) equals REG. This gives a complete characterization of the QIP systems with 
lqfa verifiers. 

Theorem 4.1 1QFA g QIP(lq fa) = REG. 

Note that the first inequality of Theorem 14. II follows from the last equality since 1QFA ^ REG. To prove 
this equality, we first claim in Proposition ^. 2l that. for any 1-way deterministic finite automaton (ldfa, in short) 
M, we can build a QIP system (P, V) in which the lqfa verifier V simulates M in a reversible fashion. Since 
any move of a ldfa is generally not reversible, we need to use an honest prover as an "eraser" which removes 
any irreversible information of M into the prover's private tape to maintain a history of the verifier's past inner 
states. This simulation establishes the desired inclusion. 

Proposition 4.2 REG C QIP 11 (lg/a). 

Proof. Let L be any regular language and let M = (Q, S, 5m) be any ldfa that recognizes L, where Q is the 
set of all inner states, £ is the input alphabet, and 5m is the transition function. We may assume for convenience 
that M's input tape has the left endmarker and the right endmarker $ because this assumption does not change 
the recognition power of the ldfa. For any pair (q,<r) of an inner state q € Q and an input symbol a £E E, 
consider the set S qt<T of all inner states that lead to q while scanning a; namely, S q>a = {p£ Q \ 5m(j>, o) = q}- 
Our goal is to define a QIP system that recognizes L with probability 1. Consider the following QIP protocol 

that simulates M by forcing a prover to act as an eraser. In what follows, let T = {ff\ U ([J qe q CT(ES S q ,c^j be 
our communication alphabet, provided that the symbol # is not in Q. The verifier V is defined to simulate 
truthfully each move of M. Let us assume that, at an arbitrary step i S [1, n + 2]z, V is in inner state p scanning 
symbol a. Now, consider the case where 5m ijp, c) = 9! in other words, M enters state q just after it scans symbol 
a in state p. The verifier V behaves as follows. In scanning the current communication symbol, whenever it is 
not V immediately rejects the input. Assuming that the communication symbol is V enters the state q 
by passing the communication symbol p to a prover. Note that, if the prover always returns V eventually 
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ends its computation at the time when the head reaches the endmarker $. If M enters an accepting inner state, 
then V simply accepts the input; otherwise, V rejects the input. We design our honest prover P to return # at 
every communication step. 

Let x be any input to our QIP system (P, V). First, consider the case where x belongs to L. Since the 
honest prover P erases the information on V's inner state at every step, V can simulate each move of M in a 
reversible fashion. Hence, V accepts x with probability 1. On the contrary, when x ^ L, a dishonest prover 
P* cannot return any symbol except for # (or any superposition of such symbols) to optimize his adversarial 
strategy because, otherwise, V can increase his rejection probability by immediately entering a rejecting inner 
state in a deterministic manner. If P* always returns however, V correctly simulates M and eventually 
enters a rejecting inner state with probability 1. Therefore, (P,V) recognizes L with certainty. □ 

To show that QIP(lg/a) C REG — the opposite direction of Proposition 14.21 we use two results: Lemmas 
14.31 and 14.41 To state these lemmas, we need the notion of resource-bounded QIP systems. Let s and t be any 
functions mapping N to N. A (t(n), s(n)) -bounded QIP system is obtained from a QIP system by forcing the QIP 
protocol to "terminate" after t(\x\) steps on each input x with s(|x|)-space bounded provers. After the i(|x|)th 
measurement, we actually stop the entire computation of the QIP system and make any non- halting inner state 
collapse to the special output symbol "/ don't knout 1 . We say that a language L has a (t(n), s(n)) -bounded 
QIP system (or a (t(n), s(n)) -bounded QIP system recognizes L) if the system satisfies the completeness and 
soundness conditions given in Section [3] for L with error probability at most e, where e is a certain constant 
drawn from the interval [0, 1/2). The following lemma connects basic QIP systems to bounded QIP systems. 

Lemma 4-3 Let L be any language in QIP(lq fa). There exists a constant c E N + such that L has an 
(n + 2, c)-bounded QIP system with a Iqfa verifier. 

Lemma 14.31 is a direct consequence of Lemma 15.51 which we shall prove in the subsequent section. Another 
ingredient, Lemma 14.41 relates to the notion of 1-tiling complexity |14| . For any language L over alphabet E, we 
define the infinite binary matrix Ml whose rows and columns are indexed by the strings over £ in the following 
fashion: any (x, y)-entry of Ml is 1 if xy E L and otherwise. Furthermore, for each n E N, Ml(ti) denotes 
the submatrix of Ml whose rows and columns are indexed by the strings of length < n. A 1-tile of Ml(ti) is a 
nonempty submatrix M of Ml{u) such that (i) all the entries of M are specified by a certain index set Rx C, 
where R,C C £-", and (ii) all the entries of M have the same value 1. For convenience, we often identify 
Rx C with M itself. A 1-tiling of Ml(u) is a set S of 1-tiles of M^(n) such that every 1-valued entry of Ml(ti) 
is covered by at least one element of S. The 1-tiling complexity of L is the function T^{n) whose value is the 
minimal size of a 1-tiling of Ml(ti). 

Lemma 4-4 Let L be any language, let c € N + , and let e E [0, 1/2). If an (n + 2, c)-bounded QIP system 
(P,V) with a lqfa verifier recognizes L with error probability at most e, then the 1-tiling complexity of L is at 
most 4 d [2\/2(l + 2d 2 )/(l - 2e)~\ 2d+1 , where d equals |Q||r||A| c for the set Q of the verifier's inner states, the 
prover's tape alphabet A, and the communication alphabet T. 

Proof. Let L be any language recognized by an (n + 2, c)-bounded QIP system (P, V) with a lqfa verifier 
with error probability at most e < 1/2. Let Q, A, and T be respectively the set of V's inner states, V's tape 
alphabet, and the communication alphabet. Recall that, for every input and every step i E [1, \x\ + l]z, 

Vp i denotes P's ith operation on x, which is described as a | A| c -dimensional unitary matrix since P is c-space 
bounded. Since P's strategy may differ on a different input, we use the notation P x to indicate that P always 
takes the strategy {L T p i } ie N+ on any given input. Write d for |Q||r||A| c and /i for (1/2 — e)/(l + 2d 2 ). 

Consider the binary matrix Ml induced from L. Our goal is to present a 1-tiling of Ml(ti), for each n E N, of 
size at most (2\V2/ ^) 2d \l/ ^ < 4 d \V2/ ^ 2d+1 = 4dj 2V2(i+2d 3 ) -^ 2 d+i_ Note thatj for any i_ va i ue d (at, gentry 
of Ml(u), since xy € L, the QIP protocol (P xy , V) accepts xy with probability at least 1 — e. Notationally, for 
each vector p and any index i, [p]i represents the i-entry of p. 

For any fixed input x, a quadruple (ji, J2, J3, J4) in the set Q x [1, \x\ + 2]z x A c x T represents a global 
configuration of the (n + 2, c)-bounded QIP system (P, V), in which V is in inner state ji with its head scanning 
the j2th cell, the communication cell contains j'3, and the prover's private tape consists of j'4. If the head 
position J2 is ignored, we call the remaining triplet (ji, J3, J4) a semi- configuration. Let I = Q x A c x T (the 
set of all semi-configurations) and, for each n E N, let I n be Q x [l,n + 2]z x A c x T (the set of all global 
configurations on any input of length n). 

In the following definition of a 1-tiling, we arbitrarily fix an integer n E N + and two strings x and y of length 
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< n satisfying that xy € L. Since V is fixed, we drop the letter V out of p aC c{x, P, V). To compute p a cc(xy, Pxy), 
we introduce two types of vectors. The configuration amplitude vector p x , y is the unique (d + l)-dimensional 
vector p x ,y whose hrst d entries are indexed by the semi-configurations. For simplicity, all the semi-configurations 
are assumed to be enumerated. For any semi-configuration i = («i,«2,*3) £ I, the i-entry [p x ,j/]i is set to be 
if %\ is a halting inner state; otherwise, [px,j/]i is the amplitude of the configuration (i\, \x\ + 1,12,13) in the 
superposition obtained after the \x\ + 1st application of U's unitary operation. In addition, the final d + 1st 
entry of p x . y indicates the probability that xy is accepted within the first |a;| + 1 steps of V. 

We further define additional (/-dimensional vectors to describe the transition amplitudes of the protocol 
(P, V). For each index j = (Ji,j2,j3,ji) G I\ v \, let rj. y be the d-dimensional vector whose entries are indexed by 
the semi-configurations i = 12, £3). If ji is an accepting inner state, then the 12, Z3)-entry of y indicates 
the transition amplitude from the configuration (ii, |x| + l,l2, is) to the configuration (ji, |a;| + .72 + ^-,33, 3a)', 
otherwise, [ri >y ]i is 0. It immediately follows that J2jei li^x.yhl 2 — 1 f° r any fixed semi-configuration i 6 /. 

Using the aforementioned vectors, we can calculate the acceptance probability p a cc{xy, P xy ) of input xy by 
the protocol (P xy , V) as follows: p acc (xy, P xy ) = ^2 Jcl y \p' x , v ^x, y ? + [Px, y ]d+i, where p' xy is the d-dimensional 
vector obtained from p x , y by deleting its last entry and the notation • denotes the inner product. 

First, letting Ci = {r € C | 3a, b[r = a + ib & \a\, \b\ < 1]}, we partition the (d + l)-dimensional complex 
space Cf x [0, 1] into (2[~v2/a*1 ^l^-ftA hyper-cuboids of diameter fx in each Ci and [0, 1]; i.e., a x square 
in each of the first d coordinates and a real line segment of length \i in the d + 1st coordinate. Note that some 
hyper-cuboids near the boundary may have diameter less than /1 in certain coordinates. Note that each hyper- 
cuboid has volume at most /i 2d+1 /2 d . Second, we associate each hyper-cuboid C with the rectangle Rc defined 
as Rc — {x I 3y'(p x ^ y , € C A xy' G L)} x {y \ 3x'(p x ^ y e C A x'y 6 L)}. To complete the proof, it suffices 
to prove that Rc is a 1-tile of M^(n) for every hyper-cuboid C whose rectangle is non-empty since, if so, every 
1-valued entry of Ml(u) is covered by a certain 1-tile Rc and therefore, the collection T of all such rectangles 
forms a 1-tiling of M L (n). Hence, the 1-tiling complexity of L is bounded by T£(ra) < \T\ = (2|\/2///|) 2d |~l///|. 

Let C be any hyper-cuboid whose rectangle is non-empty and let (x, y) be any pair of strings of length < n 
in Rc- Toward a contradiction, we assume that Rc is not a 1-tile; namely, xy g" L. This implies that, for any 
prover P* , (P*,V) accepts xy with probability < e. Since (x,y) £ Rc, there exists a pair (x',y') of strings of 
length < n such that p x . y > and p x >,y are both in C. It follows that p aC c(x'y, P x ' y ) > 1 — e since x'y € L. Now, 
consider the special prover P' that simulates P xy i while reading x and then simulates P x > y while reading y. By 
the definition of P', it follows that p acc (xy,P') = J2jei M \Px,y' ' ^x',y\ 2 + [Px,y']d+i- 

We wish to claim that p acc (xy, P') > e. The difference between p aC c(xy, P') and p a cc(x'y, P x > y ) is upper- 
bounded by: 



\Pacc{%y, Pxy) Pacc(% V, P X 'y)\ 

< \[Px',y]d+l - [Px,y']d+l\ + ^ 



< \[Px>, y }d+l - [Pxy}d+l\+J2J2\([Px, y '}i[Px, y '}i' - \P' X ' , y W X ' ,y]\')K' JA^ X > ,y]l 

j U' 

The first term | [Pz'^d+i — [Px,y']d+i| is at most fj, since p x >. y and p x ,y' are in the same hyper-cuboid. The last 



term is also bounded above by 2/x£\ J2i,i> ^Vi^ 1 , y ]l' 



This comes from the following bound: 



'x',yl 



'x',yli' 



< ItPx.v'liCtPx.v'll' " [Px'JiOl + \[p'x',yMPx,y']i ~ [Px'JOl < V 



This term 2/i ft, Jift, J* is further bounded by 2/i£.., \K>, y ]l\ VEj \K>Jt>\ 3 usin S the 

Cauchy-Schwarz inequality and is thus at most 2^id 2 . Overall, the term \p a cc{xy,P') — p a cc{x'y, P x > y )\ is 
upper-bounded by /i(l + 2d 2 ), which also equals 1/2 — e by the choice of /1. Therefore, the desired inequality 
Pacc{xy, P') > 1/2 > e follows immediately from p a cc(x'y, P x 'y) > 1 — £■ This implies that (P',V) accepts xy 
with probability > e. This contradicts our assumption that Pacc(xy, P*) < e for any prover P* . Therefore, Rc 
is a 1-tile of M L (n). □ 

At length, we obtain the containment QIP(l<7/a) C REG by combining Lemmas 14 . 31 and 14 . 41 which indicates 
that every language in QIP(lg/a) has 1-tiling complexity 0(1). Recall from ^3] that a language is regular if 
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and only if its 1-tiling complexity is bounded above by a certain constant. Therefore, it immediately follows 
that QlP(lqfa) C REG, as requested. This completes the proof of Theorem 14. II 

5 Two- Way QFA Verifiers against Mighty Provers 

We have seen in the previous section that, using interactions with provers, lqfa verifiers can exercise a re- 
markable power of recognizing the regular languages. This section turns our interest to the 2qfa- verifier QIP 
systems; namely, QIP(2<7/et) and QIP (2q fa, poly-time). First, observe that a verifier can completely elimi- 
nate any intrusion of a prover by simply ignoring the communication cell (i.e., applying the identity opera- 
tion). This observation yields the following simple containments: 2QFA C QIP (2q fa) and 2QFA(poly-time) C 
QIP (2q f a, poly-time) . 

Now, we demonstrate the power of QIP (2q fa, poly-time). 

Theorem 5.1 REG g QIP (2qf a, poly-time) £ AM(2pfa). 

The first proper containment follows immediately from the facts that REG g 2QFA(poly-time) [121 and 
2QFA(poly-time) C QIP (2q fa, poly-time). To prove the second separation, we first introduce a variation of 
Pal, briefly called Pal#, which is defined as Pal# = {x#x R | x € {0, 1}*} over the alphabet {0, 1,#}, where 
# is a separator not in {0, 1}. Similar to Pal |17l Theorem 3.4], we can show that this language Pal# does not 
belong to AM(2pfa). In the following lemma, we further claim that Pal# is indeed in QIP (2q fa, poly-time). 
Theorem 15 . II naturally follows from this lemma. 

Lemma 5.2 For any constant e £ (0, 1/2], Pal# G QIPi 1 _ e (2q fa, poly -time). 

Proof. We slightly modify the classical IP protocol given in ^] for Pal. Let £ = {0, 1,#} be our input 
alphabet, let T = {0,1, #} be our communication alphabet. Let e be any error bound in (0,1/2] and set 
d = [~log 2 (l/e)]. Note that d > 1 since e < 1/2. Our QIP system (P,V) for Pal# is given as follows. We 
begin with the description of the 2qfa verifier V who runs in worst-case linear time. Recall that the verifier's 
head is initially scanning the endmarker with the blank symbol # in the communication cell. Let x be any 
input string. The verifier runs the following quantum algorithm by stages, creating the total of 2 d independent 
computation paths. The initial stage is assumed to be s = A, the empty string. 

Repeat the following procedure (*) until |s| = d. During this procedure, V always unalters the 
communication cell (such a verifier is said to make a one-way communication). Assume that V is in 
stage s S {O,!.}^- 1 . 

(*) In the first phase, the head moves rightward. If there is no # in x, then V rejects x when V 
scans the right endmarker. In scanning V generates a superposition of two independent branches 
by entering two inner states qi iS and q2, s with the equal amplitude \j\[2. In the branch starting 
with qi jS , the head moves leftward; in the other branch with q2. s , it moves rightward. During this 
phase, whenever a prover returns any non-blank symbol, V rejects x immediately. In the second 
phase, visiting each cell, V receives a communication symbol, say a, from a prover. The head checks 
whether it is currently scanning a in the input tape unless the head arrives at an endmarker. If V 
discovers a discrepancy, then it enters a rejecting inner state. When the head reaches an endmarker, 
V rejects a; if a prover sends a non-blank symbol. The head at the left endmarker § stays still for 
another step and enters go,sO whereas the head at the right endmarker S enters qo.si by moving right 
to £ (since the input tape is circular"). Go to the next stage. 

Along each computation path s, if x is not yet rejected after executing (*) d times, then V enters 
an accepting inner state. 

Table n describes the formal transitions of V. Note that the running time of V is 0(n) even in the worst case. 
Consider the case where x — y^y R for a certain string y. In each round, the honest prover P must pass the 
string y R bit by bit to the verifier after V splits into two branches. With this honest prover P, V never enters 
any rejecting inner state. Hence, after d rounds, V finally accepts x with probability 1. 

Next, assume that x is not in Pal#. It suffices to consider only the case where x is of the form y#z R since, if 
there is no V rejects x with probability 1. In each round, since V makes only one-way communication with a 

II The circularity of the input tape is used to simplify the description of the transitions and is not necessary for the lemma. 
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Hl<?o, s >l#) 
V^\qi, s )\a) = 

v$W , s )\#) 

V#Wo,s)\#) 

Wo,.>l#> 
K|ft, s )|a) = 




l%,s)|a) Kki,a>|a') 



ko, s0 )l#) 

\n, s )\a) 
\n, s )\b) 




D(qx, s ) = - 
D(q' , s ) = 1 
D(qa,si) = 1 



1 



D{q 2 ,s) = 1 
D(q , s0 ) = 



Table 1: Transitions of V for PaZ # with stage s G {0, l}- d ~\ i G {1, 2}, a G {0, 1}, a' G T with a 7^ a', and 6 G T. 
The rejecting inner states are ro, s and r^ s . The unitary operator for each a G S acts on the Hilbert space 
spanned by Q x T. The transition function (5 of V is then induced by setting S(q, a, 7, 5', 7', d) = (g', 7'|£/<r|g, 7) 
and d = D(q) for any q,q' £ Q and any 7, 7' G T. 

dishonest prover, the prover's visible configuration is exactly the same along two branches. In other words, the 
prover answers in exactly the same way along these two branches. In the second phase, a dishonest prover P* 
may return a superposition of and 1. Since V's two branches never interfere with each other in each round, 
V can eliminate at least one of them by entering a rejecting inner state. This gives the rejection probability 
of at least 1/2 since the squared magnitude of the superposition obtained along each branch is exactly 1/2. 
Since we repeat (*) d times, the total rejection probability sums up to at least $D i=1 2~ l = 1 — l/2 rf , which is 
lower-bounded by 1 — e by the choice of d. Thus, V rejects x with probability > 1 — e. Therefore, (P, V) is a 
(1,1 — e)-QIP system that recognizes Pal#. □ 

Supplementing Theorem l5.ll we now present an upper bound of QIP(2g/ a, poly-time): with an appropriate 
choice of amplitudes, QIP(2g/a, poly-time) is located in the complexity class NP, where NP is the class consisting 
of all languages recognized by nondeterministic Turing machines in polynomial time. This can be compared 
with a result of Dwork and Stockmeyer |17|. who proved that AM(2pfa) S IP (2pf a, poly-time) C PSPACE. 

Theorem 5.3 QIPc(2g fa, poly -time) C NP. 

To show the desired upper-bound of QIP^(2g/ a, poly-time) , we need the following lemma, which is similar 
to Lemma EH 

Lemma 5-4 Every language in QIP(2g /a, poly -time) has a (t(n), clog n + c) -bounded QIP system for a certain 
polynomial t and a certain constant c > 0. 

Lemma |5.4I (as well as Lemma |4.3t directly comes from the following lemma whose proof is based on the 
result of Kobayashi and Matsumoto |3D]. Lemma f5 . 51 states that, without changing the acceptance probability, 
the prover's visible configuration space can be reduced in size to the verifier's visible configuration space. 

Lemma 5. 5 Let (P, V) be any QIP system with a 2qfa ( lqfa, resp.) verifier and let Q,T be respectively the sets 
of all inner states and of all communication symbols. There exists another prover P' that satisfies the following 
two conditions: for every input x and every i G N + , (i) the prover's ith operation Up, i is a |Q||r|(|x| + 2)- 
dimensional (\Q\ \Y\- dimensional, resp.) unitary operator, and (ii) (P',V) accepts x with the same probability 
as (P, V) does. 

Proof. Take an arbitrary QIP system (P, V) with the set Q of all inner states of V, the communication 
alphabet T, and the transition function 8 of V. In this proof, we consider only the case where V is a lqfa. The 
remaining case where V is a 2qfa can be similarly proven if we further include the information on V's head 
position. 

For convenience, we view our QIP system (P, V) as a quantum circuit of three registers. The first register 
represents the inner state of V together with the head position of the input tape, the second register represents 
the communication cell, and the third register represents a prover's private tape. Let x be any input of length n. 
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Recall the Hilbert spaces V n , -M, and V associated with (P, V) on input x. The Hilbert space V n is the tensor 
product of the \Q\ -dimensional space V and the (n + 2)-dimensional space V' n . Henceforth, we can omit the 
description of qubits on V' n since V is a lqfa. The initial superposition of (P, V) is |xo) = l<7o)|#)|A). Note that, 
at each step i G [l,n+ l]z, without changing V's acceptance probability, we can swap the application order of 
V's ith measurement E non and P's ith operation Up^ For each index i £ [l,n + l]z, the three superpositions 
\4>i), \ipi), and |xi) are inductively defined as follows: \xi) = E non \ipi), \ipi) = Up^fa), and = Uf\xi-i). In 
addition, let |^ n +2) = Ug\xn+i), which is the superposition obtained just before the final measurement. 

For brevity, write V for the |Q||r|-dimensional Hilbert space that corresponds to the private tape of a 
\Q\ |r|-space bounded prover. Our goal is to define the prover P' that works on M. £g> V' . Hereafter, we define 
the strategy {Up, i }i S N+ 01 P' on input x. For convenience, set |xo) = Ixo)- It follows from page 110] that, 
for every index ie [l,n+ l]z, there exists a vector in V ® M. ® V satisfying that tr-p/ I^XV'il = trpji/jjXV'il 
since the dimension of V' is the same as that of \>®M.. We further define the vectors \x'i) and |(/^) as follows: let 
|X-) = E non \ipl) for i £ [l,n+l]z and |#) = t^lxU) for any i € [l,n+2] z . Note that tr^l^iX^xl = tr^'iX^i I- 
Now, fix j G [2,rt + 2]z arbitrarily. Since Uf and -E„ on act on neither V nor P', we obtain: 

trH^X&l = f/f^nonCtrplVi-lXV'i-lD^nonC^) 1 = ^nonCtr^l^-lX^-lD-^on^) 1 = tr^l^X^I, 

which further implies: for any z G [l,n+ l]z, 

^M®vWi){^'i\ = tr M ® v \ipi)(ipi\ = trMapl&X&l = trAf(87"|0 / iX^il) 

where the second equality comes from the fact that C/p 4 is applied only to the space Since Iym^V' WiA^'i I = 

toM®V'\ ( t > 'iA < l ) i\i there exists a unitary operator L/j acting on M ® T 3 ' satisfying that (7® E/i)|$) = |^) jSEHSHj- 
The desired operation /7p, i of P' is set to be this I ® f/j. 

Next, we compare the acceptance probabilities of the two QIP systems (P, F) and (P',F). We have 
tr v \i> l ){i> l \ = tr-p/|^)(^'| for every i G [l,n+ l]z as well as trpl^n+aX^n+al = tr-p'|^ +2 )« +2 |- Thus, for 
every i G [l,n + 2]z, the acceptance probability of x produced by the ith measurement of (P, V) equals the 
acceptance probability of x caused by the ith measurement of (P', V). This completes the proof. □ 

Lemma lh. 51 lets us focus our attention only on (nP^, 0(log(n)))-bounded QIP systems. To simulate such 
a system, we need to approximate the prover's unitary operations using only a fixed universal set of quantum 
gates. Lemma 15 . 61 relates to an upper bound of the number of quantum gates necessary to approximate a given 
unitary operator. The lemma, explicitly stated in can be obtained from the Solovay-Kitaev theorem |27II35| 
following the standard decomposition of unitary matrices. We fix an appropriate universal set of quantum gates 
consisting of the Controlled-NOT gate and a finite number of single-qubit gates, with C-amplitudes, that 
generate a dense subset of SU(2) with their inverse. Write \og k n for (logn) fc for any constant k G N + . 

Lemma 5.6 For any sufficiently large k G N + , any k-qubit unitary operator Uk, and any real number e > 0, 
there exists a quantum circuit C of size at most 2 3k log 3 (1/e) acting on k qubits such that \\Uc — Uk\\ < e, where 
Uc is the unitary operator corresponding to C, where \\A\\ = sup^^o ll-^-l0)ll/lll^)ll- 

A quantum circuit C built in Lemma 15.61 can be further encoded into a binary string, provided that the 
encoding length is at least the size of the quantum circuit. This enables us to prove the simulation result of any 
bounded QIP system with C-amplitudes. We say that a function / from N to N is polynomial-time computable 
if there exists a deterministic Turing machine that, on any input 1™, outputs l^ n \ 

Proposition 5.7 Let s and t be any polynomial-time computable functions from N to N. Any language that 
has a (t(n), s(n)) -bounded QIP system with a 2qfa verifier using C-amplitudes belongs to the complexity class 
NTIME(n «t(n)2 ( s ("» log° (1) f(n)). 

The proof of Proposition 15 . 71 is outlined as follows. Given a bounded QIP system, we first guess a binary 
string that encodes a quantum circuit representing the prover's strategy. We then simulate the verifier's move 
followed by the prover's operation. This simulation can be done deterministically by listing all the verifier's 
configurations and simulating their amplitudes at each step. After each step of the verifier, we calculate the 
probability of reaching any halting configuration instead of performing measurement. Now, we give the formal 
proof of Proposition 15. 71 

Proof of Proposition 15771 Let (P,V) be any (t(n), s(n))-bounded QIP system with a 2qfa verifier and let 
A be the language recognized by (P,V) with error probability at most 1/2 — e for a certain fixed constant 
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e e (0, 1/2]. Let x be any input string of length n. By translating the prover's tape alphabet A to {0, l}r io sl A ll 
and the communication alphabet T to {0, l}r i °sl r ll ) we can assume without loss of generality that our prover 
uses at most [log |A|]s(n) qubits on his private tape and writes [log |T|]-qubit strings in the communication 
cell. Now, let s'(n) = [log |A|]s(n) + [log |T|] for any n E N. 

A prover comprises a series of t(n) unitary matrices on s'(n) qubits, say Ux, U2, • ■ ■ , U t i n y For each U of 
such matrices, Lemma f5.6l gives a quantum circuit Cu of size at most 2 3s ^ log 3 (dt(n)) such that the unitary 
operator associated with Cu approximates U to within X/dt[n), where d is a constant satisfying d > 2/e. This 
makes it possible to replace the prover P by the series of t(n) quantum circuits (C^, CV 2 , . . . , Cj/ t , >), which is 

hereafter abbreviated C. Note that the cumulative approximation error is bounded above by gj^-j = 1/d, 

which is smaller than e/2. Using this C as a prover, V proceeds his computation and accepts (rejects, resp.) x 
with probability > (1/2 + e) — e/2 = 1/2 + e/2 if x € A (x £ A, resp.). Choose an effective encoding (C) of 
C satisfying that |(C)| < ct(n) ■ 2 3s W \og 3 (dt{n)) for a certain constant c > 0. Note that any configuration of 
(C, V) requires s'(n) + O(logrt) qubits. 

Using the encoding (C), we give a classical simulation of the computation of (C,V) on input x. Note that 
the verifier V can be represented by the product of t(n) + 1 unitary matrices of dimension polynomial in n 
and the "prover" C consists of t(n) unitary matrices of dimension 2 s ( n \ Note that all the gates in C and 
verifier's transition function use only polynomial-time approximable amplitudes. Within time polynomial in n 
and logt(n), we can approximate such amplitudes to within t ^^ r(n) for any fixed polynomial r. By choosing a 
sufficiently large polynomial r, we can deterministically simulate with high accuracy the computation of (C, V) 
in polynomial time. Such a simulation gives an approximation of the acceptance probability p acc (x,C,V). 
Now, we accept the input x if the approximated acceptance probability exceeds 1/2, and reject x otherwise. 
For a certain polynomial p independent of n, we therefore obtain a t(n)2°^ n ^ p(n, log t(n) )-time deterministic 
algorithm that approximately simulates V with a fixed prover C . 

At last, we consider the following nondeterministic algorithm A: 

On input x (n = \x\), nondeterministically guess (C), where C is a series of t(n) quantum cir- 
cuits of size < 2 3s (™) log 3 (dt(n)) . If the aforementioned deterministic simulation of (C, V) leads to 
acceptance, then accept x, or else reject x. 

It is easy to verify that A recognizes L in time p'(n, logt(n)) • 2°^ s ( n ^t(n) for an appropriate polynomial p' . 
Therefore, L belongs to NTIME(7i°( 1 )i(n)2°( s ( n )) log° (1) t{n)). □ 

We return to the proof of the second part of Theorem 15. 31 Take any language L in QIP^(2q fa, poly-time). 
Lemma |5.4I guarantees the existence of a bounded-error (t(n), s(n))-bounded QIP system recognizing L using 
C-amplitudes, where t(n) is a polynomial and s(n) is a logarithmic function. From Proposition 15. 71 it follows 
that L belongs to the complexity class NTlME(n 0( - 1 H(n)2 0( - s(n ^ log° (1) t(n)), which clearly coincides with NP. 
This ends the proof of Theorem l5.3l 

In the end of this section, we present a closure property of QIP systems with 2qfa verifiers. 

Proposition 5.8 QlY(2qfa) and QIP (2q fa, poly -time) are closed under union. 

Proposition l5.8l is shown in the following fashion. For any two 2qfa-verifier QIP systems (Pi, V\) and (P2, V2) 
that respectively correspond to L\ and L2, the verifier for L\ U L2 first asks a prover to choose the minimal 
index i € {1,2} for which (Pi,Vi) accepts x (if i exists). The verifier then simulates the protocol (Pi,Vi) to 
check whether (Pi, Vi) truly accepts x. The formal proof below shows the validity of this protocol. 

Proof of Proposition I5T51 We prove only the closure property of QIP (2q fa) under union because a similar 
proof shows the closure property of QIP (2q fa, poly-time). Take any two languages L\,L2 € QlP(2qfa) and, 
for each i 6 {1,2}, choose a QIP system (p, V;) that recognizes Li with error probability < e, where e is any 
fixed constant in [0, 1/2). Without loss of generality, we may assume that the set of all inner states of V\ and 
that of V2 are mutually disjoint. Consider the following protocol of a new verifier V to determine whether any 
given input x belongs to L\ U L2. At the first move, V sends the communication symbol # to a prover without 
moving its tape head and waits for the prover's reply i S {1, 2}. Whenever the reply i is neither 1 nor 2, V 
immediately rejects x to prevent the prover from tampering. On the contrary, if i is truly in {1,2}, then V 
simulates Vi. On any input x in L\ U L2, our honest prover P first returns the minimal index i G {1,2} such 
that x £ Li and then behaves like Pj. 
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Henceforth, we prove that (P,V) recognizes Li U £2- Let x be an arbitrary input. First, assume that 
x 6 L\ U Ij2- Obviously, if a; € L\, then the protocol (P, V) simulates (Pi, Vi) and otherwise, (P, V) simulates 
(P2, V2). Hence, V accepts x with probability at least 1 — e. Next, assume that x L\ U L^- To maximize the 
acceptance probability of V on the input x, a dishonest prover should return either 1 or 2 (or their superposition). 
However, V simulates Vi when he receives i, and the computation paths of V that simulate V\ and V% do not 
interfere with each other. Thus, for any prover P* , (P* ,V) rejects x with probability at least 1 — e. This 
completes the proof. □ 



6 How Often is Measurement Performed? 

Measurement is one of the most fundamental operations in quantum computation. Although a measurement 
is necessary to "know" the content of a target quantum state, the measurement collapses the quantum state 
and thus causes a quantum computation irreversible. Since a qfa uses only a finite amount of memory space, 
the number of times when measurements are conducted affects the computational power in general. Recall 
measure-once lqfa's or mo-lqfa's from Section^ We define an mo-lqfa verifier as a lqfa verifier who does not 
perform any measurement until he applies the final unitary operation while visiting the right endmarkcr $. This 
indicates that a measurement takes place only once after the verifier makes exactly \x\ + 2 moves on input x. 
We use the restriction (mo-lqfa) to indicate that a verifier is an mo-lqfa. This section makes a comparison 
between mo-lqfa verifiers and lqfa verifiers in our QIP systems. As mentioned in Section^] mo-lqfa's and lqfa's 
are quite different in power because of the different numbers of measurement operations performed during a 
computation. 

In what follows, we show that (i) the QIP systems with mo-lqfa verifiers are more powerful than mo-lqfa's 
alone and (ii) mo-lqfa verifiers are more prone to be fooled by dishonest provers than lqfa verifiers. 

Theorem 6.1 MO-1QFA g QW{mo-lqfa) g QIP(lg/a). 

Theorem lfi.ll is a direct consequence of Proposition ^. 21 which refers to a closure property of QIP (mo-lq f 'a) . 
Conventionally, a complexity class C is said to be closed under complementation if, for any language A over 
alphabet E in C, its complement E* — A is also in C. 

Proposition 6.2 QIP(mo-l<7/a) is not closed under complementation. 

Theorem 16.11 follows from Proposition 16.21 because QIP(lg/a) (= REG) and MO-1QFA are known to be 
closed under complementation |34j . 

To prove Proposition ^. 21 it suffices to show that (i) the unary language L a = {a}* — {A} is in QIP X ^mo-lqfa) 
and (ii) the language {A} is not in QIP(mo-lg/a). We first show that L a 6 QIP 1 1 (mo-lqfa). We set out alpha- 
bets E and T as E = {a} and T — {a, #}. The transition of our verifier V is given in Tabled At the first step, 
V stays in the initial inner state qo with passing the symbol # to a prover. If the input is A, then, in reaching 
the endmarker $ in state qo, V enters the rejecting inner state q re j- Clearly, V rejects the input with certainty 
no matter how the prover behaves. In the opposite case where the input is nonempty, if V scans a for the first 
time in the initial inner state qo, V sends the symbol a to a prover and then enters the inner state q±. When the 
honest prover modifies it back to #, V keeps the current inner state q± and the current communication symbol 
until V reads $. Finally, V enters the accepting inner state q aC c- With the honest prover, V correctly accepts 
the input with certainty. Hence, (P, V) recognizes L a with certainty. 





l<?o>]#> 






V a \q )\#) = 


\Qi)\a) 


V a \qi) 


l#) = ki)l#> 


V$\q )\b) - 


Qrej)\b) 


V $ \qi) 


|#) = kacc)|#) 



Table 2: Transitions of V for L a with b £ {a, ff}. The unitary operator V a for each a € E acts on the Hilbert 
space span{|q, 7) | (q, 7) £ Q x T}. The transition function S of V is then induced by letting S(q, a, 7, q' , 7', 1) = 
W> l'\Va\q, 7) for every q,q' g Q and 7, 7' € T. 

We next prove the remaining claim that {A} ^ QIP(?7Jo-lg/a). More generally, we claim that no finite 
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language belongs to QlP(mo-lqfa). This claim is a consequence of the following lemma, which gives a more 
general limit to the power of the QIP systems with mo-lqfa verifiers. 

Lemma 6. 3 Let L be a language over a nonempty alphabet S and let M be its minimal deterministic automa- 
ton. Assume that there exist an input symbol a € X. an accepting inner state q\, and a rejecting inner state qi 
satisfying: (1) if M reads a in the state q\, then M enters the state q2 and (2) if M reads a in the state q2, then 
M stays in the state q2- Figured illustrates these transitions. The language L is then outside of QIP (mo-lqfa). 




Figure 2: Transitions included in the minimal automaton for L 

To prove Lemma 16.31 we use the following well-known result in 

Lemma 6.4 Let U be any unitary matrix and let e be any positive real number. There exists a number 

n G N + such that ||(/— U n )x\\ 2 < e for any vector x with \\x\\ 2 < 1. 

We give the proof of Lemma 

Proof of Lemma l6.31 From the characteristics of the minimal automaton, there exists an input string y G E* 
such that M enters q\ after reading y and enters q^ after reading ya n for any positive integer n. Hereafter, we 
fix such a string y. Assume toward a contradiction that L belongs to QIP (mo-lqfa). Take a real number 77 > 0, 
an honest prover P, and an mo-lqfa verifier V satisfying the following: (P, V) accepts y with probability at 
least 1/2 + Ty while, for any prover P* and any number n G N + , (P* , V) rejects ya n with probability > 1/2 + 77. 
Consider the following prover P' that works on input ya n : P' first simulates P on input y while V is reading y 
and, whenever V passes a symbol s to P' , P' returns the same s to V. 

To lead to a contradiction, we utilize Lemma ffi. 41 Let \(f> y ) be the superposition of configurations obtained 
after V finishes reading y. Let V& be the unitary operator corresponding to the transition of V while scanning 
symbol b G E. By setting e = r/ 2 , Lemma 16.41 guarantees the existence of a positive integer n such that 
lll^y) - Va\4>y)\\ 2 < V 2 , which equals \\\(f> y ) -V™\<p y }\\ < n. For readability, we write p acc (y, P) for p acc (y, P, V). 
Since Pacc(y,P) a- n d Pacc(yi n , P') are obtained respectively by measuring the final superpositions V%\<j) y ) and 
V$V£\(j) y ), we conclude: 

\Pacc(y,P)~Pacc(ya n ,P')\ < || V $ \ cf> y ) - V t V? \ <j> y ) \\ = \\ |^> - V^ y ) \\ < T,, 

where the first inequality is a folklore (see, e.g., |44l Lemma 8]). Since p acc (y,P) > 1/2 + rj, it follows that 
Pacc(ya n , P') > (1/2 + J?) — 17 = 1/2, which contradicts our assumption that, for any prover P* , p a cc(ya n , P*) < 
1/2 - 77 < 1/2. Therefore, L QIP (mo-lqfa). □ 

Earlier, Brodsky and Pippenger gave a group-theoretic characterization of MO-1QFA. Such a charac- 
terization is not yet known for QIP(mo-lqfa). 

7 Is a Quantum Prover Stronger than a Classical Prover? 

Our prover can perform any operation that quantum physics allows. We want to restrict the power of a prover. 
If the prover is limited to wield only "classical" power, we may call such a prover "classical." More precisely, 
a prover is called classical if the prover's move is dictated by a unitary operator whose entries are either 0s or 
Is. By contrast, we sometimes refer to any standard prover as a quantum prover. Remember that any classical 
prover is a quantum prover. Although any classical-prover QIP system seems to be directly simulated by a 
similar QIP system using a quantum prover, it is not yet known that this is truly the case in general because, 
intuitively, more powerful the prover becomes, more easily may the weak verifier be convinced as well as fooled. 
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Hereafter, the restriction (c-prover) indicates that a prover behaves classically. In our qfa-verifier QIP systems, 
a classical prover may play an essentially different role from a quantum prover 's. 

We consider the lqfa- verifier case first. Similar to the quantum prover case, we can show that 1QFA C 
QIP (lqfa, c-prover). By expanding this containment, we can show the following stronger containment, which 
makes a bridge between quantum provers and classical provers. 

Proposition 7.1 QIP (lqf a) C QIP (lqfa, c-prover). 

Proof. It is easy to show in a way similar to Proposition 14.21 that QIP(lqf a, c-prover) contains all regular 
languages. Since QIP(lqfa) = REG by Theorem 14. II QlP(lq fa, c-prover) therefore includes QIP(lg/a). □ 

Whether QiP(l<7/a, c-prover) coincides with QIP(lg/a) is unclear due to the soundness condition of a QIP 
system. 

Next, we examine the 2qfa-verifier case. Unlike the lqfa verifier case, any containment between QIP(2q/a) 
and QIP (2q fa, c-prover) is unknown. Nonetheless, we can easily show that QIP(2g fa, poly-time, c-prover) 
contains 2Q¥ A(poly-time). The proper inclusion REG 5 QIP (2q fa, poly-time, c-prover) is a direct consequence 
of the result in [35] that REG S 2QFA(poly-time) . The following theorem greatly strengthens this separation. 

Theorem 7.2 1. AM(2pfa) § QIP (2qf a, c-prover). 

2. AM(2pfa,poly-time) S QIP(2q fa, poly-time, c-prover) (jt AM(2pfa) . 

Proof. In the proof of Lemma 15.21 we have shown that Pal# is in QIP (2qf a, poly-time). Notice that 
the same proof works for classical provers. This places Pal# in QIP(2g fa, poly-time, c-prover). Hence, sim- 
ilar to Theorem 15. II the separation between AM(2pfa) and QlP(2qf a, poly-time, c-prover) naturally follows. 
This separation further leads to the inequality between AM(2pfa) and QIP(2q/a, c-prover) (also between 
AM(2pf a, poly-time) and QIP (2q fa, poly-time, c-prover)). Therefore, in this proof, it suffices to show that 
AM(2p/a) C QIP (2qfa, c-prover). Since our proof works for any time-bounded case, we also obtain the re- 
maining claim that AM(2pf a, poly-time) C QIP(2q fa, poly-time, c-prover). 

The important starting point is the fact that the complexity class AM(2p/a) can be characterized by 
bounded-error finite automata with probabilistic and nondeterministic moves. Such an automaton is called a 
2npfa in ^1]. Let L be any language in AM(2pfa) over alphabet E. Take a finite automaton M = (Q, E, 6 m) 
with nondeterministic states and probabilistic states that recognizes L with error probability at most e, where 
< e < 1/2. To simplify our proof, we make two inessential assumptions for M's head move. Assume that (i) 
M's head always moves either to the right or to the left and (ii) whenever M tosses a fair coin, the head moves 
only to the right. Based on this M, we shall construct a QIP system (P, V) for L. 

Let x be any input of length n. The verifier V carries out the following procedure, in which V simulates M 
step by step with Q' — {p,p \ p G Q} as the set of inner states and T = (Q' x {±1})U{#, $} as the communication 
alphabet, where p is a new inner state associated with p and $ is a new non-blank symbol. Consider any step 
at which M tosses a fair coin in probabilistic state p by the transition 5m(p, cr) = {(po, 1), (pi, 1)} for certain 
distinct states po,pi G Q. The verifier V checks whether the communication cell is blank. If not, V rejects x at 
this simulation step; otherwise, V makes the corresponding transition V a \p)\jf) = -^{\po)\(Pi 1)) + |Pi)|(Pi I)))- 
Here, V a is the unitary operator defined by S(p, a, 7, q, 7', D(q)) = (q, "f'\V a \p, 7) with the transition function 
5 of V and D is the function from Q' to {0,±1}. The verifier expects a prover to erase the symbol p in the 
communication cell by overwriting it with the blank symbol This erasure guarantees V's move to be unitary. 

Next, consider any step at which M makes a nondeterministic choice in state p by the transition Sm{p, c) = 
{(.Poi^o): (Pii^i)) • ■ ■ 1 (Prm d rn )}, where m G N. Notice that a deterministic move is treated as a special case 
of a nondeterministic move. In this case, V takes two steps to simulate M's move. The verifier V enters 
a rejecting inner state immediately unless the communication cell contains the blank symbol. Now, assume 
that the communication cell is blank. Without moving its head, V first sends the designated symbol S to a 
prover, requesting a pair (p',d ! ) in Q x {±1} to return. This is done by the transition V a \p)\#) = The 
verifier forces a prover to return a valid nondeterministic choice (i.e., (p' , d!) G Sm(p, c)) by entering a rejecting 
inner state if the prover writes any other symbol. Once V receives a valid pair (p' ,d'), V makes the transition 
V a \p) \(p' , d')) = \p')\(p,d')) and expects a prover to erase the communication symbol (p,d'). 

The honest prover P must blank the communication cell at the end of each simulation step of V and return 
a "correct" nondeterministic choice on request of the verifier V. If x G L, there are a series of nondeterministic 
choices along which M accepts x with probability at least 1 — e. With the help of the honest prover P, V can 
successfully simulate M with the same error probability. Consider the case where x ^ L, on the contrary. In 



15 



this case, no matter how nondeterministic choices are made, M rejects x with probability at least 1 — e. Take a 
dishonest classical prover P* that maximizes the acceptance probability of V on x. This prover P* must clear 
out the communication cell whenever V asks him to do so since, otherwise, V immediately rejects x. Since P* is 
classical, all the computation paths of V have nonnegative amplitudes which cause only constructive interference. 
This indicates that P* cannot annihilate any existing computation path of V. On request for a nondeterministic 
choice, P* must return any one of valid nondeterministic choices. With a series of nondeterministic choices of 
P* , if V rejects x with probability less than 1 — e, then our simulation implies that M rejects x with probability 
less than 1 — e. This is a contradiction against our assumption. Hence, V rejects x with probability at least 
1 - e. Therefore, (P, V) is a (1 - e, 1 - e)-QIP system for L. □ 

In the above proof, we cannot replace a classical prover by a quantum prover. The major reason is that a 
quantum prover may (i) return a superposition of two nondeterministic choices instead of choosing one of the 
two choices and (ii) use negative amplitudes to make the verifier's quantum simulation destructive. 

In the end of this section, we present a QIP protocol with a classical prover for the non-regular language 
Center, which is known to be in AM(2p/a) but not in ANL(2pf a, poly-time) |17j . In our QIP system, a prover 
signals the location of the center bit of an input and then a verifier tests the correctness of the location by 
employing the quantum Fourier transformation (QFT, in short) in a fashion similar to |32j . 

Lemma 7.3 For any e € (0,1), Center G QIPj i_ e (2qf a, poly-time, c-prover). 

Proof. Let e be any error bound in the real interval (0,1) and set N = |~l/e~|. We give a QIP protocol 
witnessing the membership of Center to QIPi i_ e (2q fa, poly-time, c-prover). Let £ = {0,1} be our input 
alphabet and let L = 1} be our communication alphabet. Our QIP protocol comprises four phases. Let 
x be an arbitrary input. In the first phase, the verifier checks whether |x| is odd by moving the head toward 
the right endmarker $ together with switching two inner states qo and q\. To make deterministic moves, the 
verifier forces a prover to return only the blank symbol When |x| is odd, the verifier enters the state q% after 
stepping back to Hereafter, we consider only the case where input x has an odd length. 

In the second phase, V moves its head rightward by passing the communication symbol # to a prover 
until V receives 1 from the prover. Receiving 1 from the prover, V rejects x unless scanning 1 in the input 
tape. Otherwise, the third phase starts. During the third and fourth phases, whenever the prover changes the 
communication symbol 1 to V immediately rejects the input. Assume that the head is now scanning 1. In 
the third phase, the computation splits into N parallel branches (the first split) generating the N distinct inner 
states ri.o, r^o, ■ ■ • , r/v.o with equal amplitudes 1/ \/~N. The head then moves deterministically toward the right 
endmarker $ in the following manner: along the jth path (1 < j < N) associated with the inner state rj,o, the 
head idles for 2(N — j) steps in each tape cell before moving to the next one. When the head reaches $, it steps 
back two cells and starts the fourth phase. During the fourth phase, the head along the jth path keeps moving 
leftward by idling in each cell for j steps until the head reaches At the left endmarker, the computation splits 
again into N parallel branches by the QFT (the second split), yielding either the accepting inner state £jy or 
one of the rejecting inner states {tj | 1 < j < N}. 

The formal description of the transitions of V is given in Tabled From this table, it is not difficult to check 
that the verifier is well- formed (i.e., Uf is unitary for every x S £*). The honest prover P should return 1 
exactly at the time when the verifier scans the center bit of an input and at the time when the verifier sends # 
during the third and fourth phases. At any other step, P should perform the identity operation. 

The following is the proof of the completeness and soundness of the QIP system {P, V) for Center. First, 
consider a positive instance x, which is of the form ylz for certain strings y and z of the same length, say n. 
Since the honest prover P signals when the verifier reads the center bit of x, the first split occurs exactly after 
n steps of V from the start of the second phase. Along the jth path (1 < j < N) chosen at the first split, V 
idles for 2n(N — j) steps while reading y and also idles for (|x| — l)j steps while reading the whole input except 
for its rightmost symbol. Overall, the idling time elapses for the duration of 2n(N — j) + 2nj — 2nN, which 
is independent of j. Hence, all the TV 2 paths created at the two splits have the same length. The QFT then 
converges them to the verifier's visible accepting configuration |tjv)|#)- Therefore, V accepts x with probability 
1. 

On the contrary, suppose that x = yOz, where \y\ = \z\ = n. Consider the second, third and fourth phases. 
To minimize the rejection probability, a dishonest prover P* should send the symbol 1 at the moment when 

V scans 1 in the input tape in the second phase and then maintain 1 after the first split because, otherwise, 

V immediately rejects x and no classical prover passes both 1 and # in a form of superposition. Now assume 
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Table 3: Transitions of V for Center with b E {0, 1}. In this table, ijy is the only accepting inner state while 
Qrej,j (— 1 < j < 2iV — 1) and (1 < I < N) are rejecting inner states. The table, however, excludes obvious 
transitions to rejecting inner states when a prover changes the communication symbol 1 to # during the third 
and fourth phases. The transition function S is induced from V as S(q, a, 7, q' , 7', d) = (q' , j'\ V a \q, 7) if D(q') = d 
and otherwise. 



that the eth symbol of a; is 1 and P* sends 1 during the eth interaction, where 1 < e < 2n + 1. Note that 
e n + 1 because the center bit of x is 0. For any j S [1, N]%, let pj be the computation path following the 
jth branch generated at the first split. Along this path pj toward the left endmarker <(:, the idling time totals 
2(\x\ — e)(N — j) + 2nj = 2(n + 1 — e)(N — j) + 2nN. For any distinct values j and j' , the two paths pj and py 
have different lengths. For each of such paths, the QFT further generates N parallel paths; however, only one 
of them reach |ijv)|#). Hence, the probability of V reaching such an acceptance configuration is no more than 
1/N 2 . Since there are N paths {Pj}i<j<N , the overall acceptance probability is at most N x (1/N 2 ) = 1/N. It 
is easy to see that V rejects x with probability > 1 — 1/N > 1 — e. □ 



8 What If a Verifier Reveals His Private Information? 

The strength of a prover's strategy hinges on the amount of the information that a verifier reveals. For instance, 
when a verifier makes only one-way communication (as in the proof of Lemma l5.2|l . no prover gains more than 
the information on the number of the verifier's moves. The prover therefore knows little of the verifier's 
configurations. In Babai's "public" IP systems by contrast, a verifier completely reveals his configurations. 
The notion of "public coins" forces the verifier to pass only his choice of next moves, which allows the prover 
to reconstruct the verifier's computation. In this section, we consider a straightforward analogy of public IP 
systems in the quantum setting and call our QIP system public for convenience. Formally, we introduce a public 
QIP system as follows. 

Definition 8.1 A qfa- verifier QIP system (P, V) is called public if the verifier V writes his choice of non- halting 
inner state and head direction in the communication cell at every step; that is, the verifier's transition function 
5 satisfies that, for any x, q, k, and 7, U$\q, k, 7) = J2 q > 5 d ^(<?> x (k) 7 7; q'i £j d)\q' , k + d (mod n + 2), £), where 
£ = {q' , d) whenever q' is a non-halting inner state. 
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In particular, when the verifier V is a lqfa, we can omit the head-direction information d from the commu- 
nication symbol £ = (q',d) in the above definition since V always moves its head to the right. To emphasize 
the public QIP system, we use the restriction (public). 

Let us begin our study on the complexity class QIP (lqfa, public). 

Proposition 8.2 QlP 11 (lq fa, public) ^ 1QFA. 

Recall the language Zero. Proposition 18 . 21 is obtained by proving that Zero belongs to QIP (lqfa, public) 
since Zero resides outside of 1QFA j22j- The following proof exploits the prover's ability to inform the location 
of the rightmost bit of an instance in Zero. 

Proof of Proposition 18.21 We want to show that Zero has an error-free public QIP system (P, V) with 
a lqfa verifier. Since no lqfa recognizes the language Zero |32|. we therefore obtain the proposition. To 
describe the desired protocol (P, V), let £ = {0,1} be its input alphabet and let Q non = {qo,qi}, Qacc = 
{Qacc,o, q acc ,i, qacc-i} and Q rej = {q rej fl , q rej , i , q re3 - 1 } be respectively the sets of all non-halting inner states, 
accepting inner states and rejecting inner states of V. 

As mentioned before, we abbreviate communication symbol (q, 1) for q £ Q as q since V's head direction is 
always +1. Our communication alphabet T is thus go, qi}. The protocol of V is described in the following. 
Let x — yb be any input string, where b £ {0, 1}. The verifier V stays in the initial state go by sending the 
communication symbol qo to a prover until the prover returns #. Whenever V receives he immediately 
rejects x if its current scanning symbol is different from 0. On the contrary, if V is scanning 0, then he waits 
for the next tape symbol. If the next symbol is $, then he accepts x; otherwise, he rejects x. See Table 0] for 
the formal description of V's transitions. Our honest prover P does not alter the communication cell until V 
reaches the end of fyy and he must return # exactly when V reads the rightmost symbol of fyy. 
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Table 4: Transitions of V for Zero with i £ {0,±1}. The symbol g_i denotes 



It still remains to prove that (P, V) recognizes Zero with certainty. Consider the case where our input x 
is of the form yO for a certain string y. Since x £ Zero, the honest prover P returns # exactly when V reads 
the rightmost symbol of fyy. This information helps V locate the end of y. Now, V confirms that the current 
scanning symbol is and then enters an accepting inner state with probability 1 after it encounters the right 
endmarker. On the contrary, assume that x — yl. Clearly, the best adversary P* needs to return either go or 
# (or their superposition). If P* keeps returning qo, then V eventually rejects x and increases the rejection 
probability. Since V's computation is deterministic, this only weakens the strategy of P* . To make the best 
of the adversary's strategy, P* must return the communication symbol # before V reaches $. Nonetheless, 
although P* returns it, V is designed to lead to a rejecting inner state. Therefore, the QIP system (P, V) 
recognizes Zero with certainty. □ 

A 1-way reversible finite automaton (lrfa, in short) is a lqfa whose transition amplitudes are either or 
1. Let 1RFA denote the collection of all languages recognized by certain lrfa's. As Ambainis and Freivalds 5 
showed, 1RFA is characterized as the collection of all languages that can be recognized by lqfa's with success 
probability > 7/9 + e for certain numbers e > 0. 

Proposition 8.3 1RFA C QIP 1 ^(Iq fa, public). 

Proof. We first show that 1RFA C QIP X 1 (lg fa, public). Take an arbitrary set L recognized by a lrfa 
i 90j Qacc, Qrej, $ m) ■ Without loss of generality, we can assume that, in the transition of M, the 
initial state go appears only when M starts its computation. 

The protocol of V is given as follows. Assume that V is in inner state p scanning symbol b. Whenever M 
changes its inner state from p to q while scanning b, V does so by sending the communication symbol p to a 
prover if q is a non-halting inner state. As soon as V finds that the communication symbol has been altered by 
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Table 5: Transitions of V for L with 6 6 £ and p,q <E Q 



the prover, V immediately rejects the input. Table gives the list of V's unitary operators induced from M's 
transition function Sm- The honest prover P is the one who does not alter any communication symbol. On 
any input x, the QIP system (P, V) clearly accepts x with certainty if x € L. Consider the opposite case where 
x L. It is easy to see that the best strategy for a dishonest classical prover P* is to keep any communication 
symbol unchanged because any alteration of a communication symbol causes V to reject x immediately. Even 
with such a prover P* , V rejects x with certainty. Therefore, (P, V) recognizes L with certainty. Since L is 
arbitrary, we obtain the desired inclusion 1RFA C QIP 1 i(lqf a, public). Finally, the separation between 1RFA 
and QIP 1 1 (lqf a, public) comes from Proposition 18. 21 This completes the proof. □ 

We further examine public QIP systems with 2qfa verifiers. Similar to Theorem I7.2f 2). we can give the 
following separation. 

Theorem 8.4 1- QIP (2q fa, public, poly -time) AM(2pf a, poly-time). 
2. QlP(2qf a, public, poly-time, c-prover) AM(2p fa, poly -time). 

A language that separates the public QIP systems from AM(2pf a, poly-time) is Upal. Since Upal 
resides outside of AM(2pf a, poly-time) [TJ\ and Upal belongs to 2QFA(poly-time) the separation 

2Q¥A(poly-time) AM(2qf a, poly-time) follows immediately. This separation, however, does not directly 
imply Theorem 18 . 41 because it is not clear whether 2Q¥ A(poly-time) is included in QIP (2q f a, public, poly-time) 
or in QIP (2q fa, public, poly-time, c-prover). Therefore, we still need to prove in Lemma l8.5l that Upal is indeed 
in both QIP (2q fa, public, poly-time) and QIP(2qf a, public, poly-time, c-prover). Our public QIP system for 
Upal, nevertheless, is essentially a slight modification of the 2qfa given in |32] for Upal. 

Lemma 8.5 For any constant e € (0>1]j Upal € QIP 1 1 _ £ (2qf a, public, poly-time) D 
QIPi.i_ e (2qfa, public, poly-time, c-prover) . 

Proof. We show that Upal belongs to QlPi i- e (2q fa, public, poly-time) since the proof that Upal belongs to 
QIP X 1 _ e (2g/ a, public, poly-time, c-prover) is similar. Let N — |~l/e~| . We define our public QIP system (P, V) 
as follows. The verifier V acts as follows. In the first phase, it determines whether an input x is of the form 
m l n . The rest of the verifier's algorithm is similar in essence to the one given in the proof of Lemma [7.31 
In the second phase, V generates N branches with amplitude l/\/~N by entering N different inner states, say 
ri, T2, ■ ■ ■ , rjv- In the third phase, along the jth branch starting with rj (J G [1, N]z), the head idles for N — j 
steps at each tape cell containing and idles for j steps at each cell containing 1 until the head finishes reading 
Is. In the fourth phase, V applies the QFT to collapse all the paths to a single accepting inner state if m = n. 
Otherwise, all the paths do not interfere with each other since the head reaches the right endmarker at different 
times along different branches. During the first and second phases, V publicly reveals the information (q' , d!) on 
his next move and then checks whether the prover rewrites it with a different symbol. To constrain the prover's 
strategy, V immediately enters a rejecting inner state if the prover alters the content of the communication cell. 
The honest prover P always applies the identity operation at every step. 

We show the completeness and soundness for our QIP system (P, V). This is done in a fashion similar to 
the proof of Lemma 17.31 With the honest prover for any input x € Upal, (P,V) obviously accepts x with 
probability 1. Assume that x = m l™ with m 7^ n. Consider a dishonest prover P* who maximizes the 
acceptance probability of V on x. Against V^'s rejection criteria, the prover P* cannot change the content of 
the communication cell at any step. Since the head arrives at the endmarker $ at different moments, no two 
branches apply the QFT simultaneously. This makes it impossible for P* to force two or more branches to 
interfere. Along each branch, the probability that V enters an accepting inner state is at most 1/N 2 . Therefore, 
(P*, V) rejects x with probability bounded below by 1 — N ■ (1/N 2 ), which is at least 1 — e. □ 

As noted in the proof of Theorem l7.2l the classical public IP systems with 2pfa verifiers can be characterized 
by alternating automata that make nondeterministic moves and probabilistic moves. A natural question is 
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whether our public QIP systems have a similar characterization in terms of a certain variation of qfa's. Moreover, 
Condon et al. |14j proved that any language in XM(2pf a, poly-time) has polylogarithmic 1-tiling complexity. 
What is the 1-tiling complexity of languages in QIP (2q f a, public, poly-time)l 

9 How Many Interactions are Necessary? 

In the previous sections, we have shown that quantum interactions between a prover and a qfa verifier notably 
enhance the qfa's ability to recognize certain types of languages. Since our basic model of QIP systems forces 
a verifier to communicate with a prover at every move, it is natural to ask whether such interactions are truly 
necessary. Throughout this section, we carefully examine the number of interactions between a prover and a 
verifier in a QIP system. To study such a number, we need to modify our basic systems so that a prover should 
alter a communication symbol in the communication cell exactly when the verifier asks the prover to do so. For 
such a modification, we first look into the IP systems of Dwork and Stockmeyer |171 . In their system, a verifier 
is allowed to do computation silently at any chosen time with no communication with a prover. The verifier 
interacts with the prover only when the help of the prover is needed. We interpret the verifier's silent mode 
as follows: if the verifier V does not wish to communicate with the prover, he writes a special communication 
symbol in the communication cell to signal the prover that he needs no help from the prover. Simply, we use 
the blank symbol # to condition that the prover is prohibited to tailor the content of the communication cell. 

We formally introduce a new QIP system, in which no malicious prover P is permitted to cheat a verifier by 
tampering with the symbol ff= willfully. To describe a "valid" prover P independent of the choice of a verifier, 
we require the prover's strategy P x = {Up i } i€ fi+ on input x, acting on the prover's visible configuration space 
M. ® V, to satisfy the following condition. For each i £ N, let So = {#°°} and let Si be the collection of 
all y € ^fi n such that, for a certain element z S 1 and certain communication symbols <j, r S T*, the 
superposition f/pjer}^) contains the configuration |r)|y) of non-zero amplitude. Note that these Si's are all 
finite. For every i G N + and every y G Sj_i, we require the existence of a pure quantum state \i/j x ,y,i) in the 
Hilbert space spanned by {\z) \ z £ A^ n } for which Up^\#)\y) = \#)\i(>x,y,i)- A prover who meets this condition 
is briefly referred to as committed. A trivial example of such a committed prover is the prover Pj, who always 
applies the identity operation. A committed prover lets the verifier safely make a number of moves without 
any "direct" interaction with him. Observe that this new model with committed provers is in essence close to 
the circuit-based QIP model discussed in Section 13.21 We name our new model an interaction-bounded QIP 
system and use the new notation QIP^(lq/a) for the class of all languages recognized with bounded error by 
such interaction-bounded QIP systems with lqfa verifiers. Since QIP^(lg/a) naturally contains QIP(lg/a), 
our interaction-bounded QIP systems can also recognize the regular languages. This simple fact will be used 
later. 

Lemma 9.1 REG C QIP # (l<j/a). 

Next, we need to clarify the meaning of the number of interactions. Consider any non-halting global 
configuration in which V on input x communicates with a prover (i.e., writes a non-blank symbol in the 
communication cell). For convenience, we call such a global configuration a query configuration and, at a query 
configuration, V is said to query a word to a prover. The number of interactions in a given computation means 
the maximum number, over all computation paths 7, of all the query configurations of non-zero amplitudes 
along its computation path 7. Let L be any language and let (P, V) be any interaction-bounded QIP system 
recognizing L. We say that the QIP protocol (P, V) makes i interactions on input x if i equals the number 
of interactions during the computation of (P, V) on x. Furthermore, we call (P, V) k-interaction bounded 
if, for every x, if x € L then (P, V) makes at most k interactions on input x** and otherwise, for every 
committed prover P* , (P*,V) makes at most k interactions on input x. At last, let QIP* (lqfa) denote the 
class of all languages recognized with bounded error by fc-interaction bounded QIP systems with lqfa verifiers. 
Obviously, 1QFA C QIP* (lqfa) C QIP* +1 (lqfa) C QIP* (lqfa) for any number k G N. In particular, 
QIP* (lqfa) = 1QFA. 

As the main theorem of this section, we show in Theorem 19.21 that (i) 1-iteration helps a verifier but (ii) 
1-iteration does not achieve the full power of QIP* (lqfa). 



"Instead, we may possibly consider a stronger condition like: for every x and every committed prover P* , (P*,V) makes at 
most k interactions. 
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Theorem 9.2 QlPf (lqfa) g QlPf (Iqfa) g QlP*(lqfa). 

Theorem 19 .21 is a direct consequence of Lemma T9. 31 and Proposition ^. 41 For the first inequality of Theorem 
19.21 we use the language Odd defined as the set of all binary strings of the form O m lz, where m S N, z € {0, 1}*, 
and z contains an odd number of 0s. Since Odd ^ IQFA it is enough for us to show in Lemma 1931 that Odd 
belongs to QlPf (lqfa). For the second inequality, we shall demonstrate in Proposition 19.41 that QlPf (lqfa) 
does not include the regular language Zero. Since REG C QIP* (lqfa) by Lemma O Zero belongs to 
QIP*(lg/a) and we therefore obtain the desired separation. 

The rest of this section is devoted to prove Lemma 19.31 and Proposition 19.41 As the first step, we prove 
Lemma 19.31 

Lemma 9.3 Odd € QlPf (lqfa). 

Proof. We give a 1-interaction bounded QIP system (P, V) that recognizes Odd. Now, let £ = {0, 1} 
and r = {#,a} be respectively the input alphabet and the communication alphabet for (P, V). Let Q = 
{lo, qi, 92, q acci q re j,o, q r e 3 .i} be the set of V's inner states with Q acc = {q acc } and Q re] = {q re j,o, q re j,i}- The 
protocol of the verifier V is given as follows. With no query to a committed prover, V continues to read the 
input symbols until the head scans 1 in the input tape. When V reads 1, V queries the symbol a to a committed 
prover. If the prover returns a, then V immediately rejects the input. Otherwise, the verifier checks whether 
the substring of the input after 1 includes an odd number of 0s. This check can be done by the verifier alone. 
Table gives the formal description of V's transitions. The honest prover P, whenever receiving the symbol 
a from the verifier, returns the symbol # and writes a in the first blank cell of his private tape. Technically 
speaking, to make P unitary, we need to map visible configuration for certain y's not appeared yet in 

P's private tape to superposition \a)\(f) XtV ) with an appropriate vector \4> x ,y)- By a right implementation, we 
can make P a committed prover. 
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Table 6: Transitions of V for Odd 



We show that (P, V) recognizes Odd with probability 1. Let x be any input. First, consider the case where 
x is in Zero. Assume that x is of the form m ly, where y contains an odd number of 0s. The honest prover P 
erases a that is sent from the verifier when V reads 1. Since V can check whether y includes an odd number of 
0s, V accepts x with certainty. Next, assume that x ^ Odd. In the special case where x £ {0}*, V can reject 
x with certainty with no query to a committed prover. Now, consider the remaining case where x contains 
a 1. Assume that x is of the form m ly, where y contains an even number of 0s. The verifier V sends a to 
a committed prover when he reads 1. Note that V's protocol is deterministic. To maximize the acceptance 
probability of V, a dishonest prover needs to return # to V since, otherwise, V immediately rejects x in a 
deterministic fashion. Since V can check whether y includes an odd number of 0s without making any query to 
the prover, for any committed prover P* , (P* , V) rejects x with certainty. Since the number of interactions in 
the protocol is at most 1, Odd therefore belongs to QlPf (lqfa), as requested. □ 

As the second step, we prove Proposition 19.41 The language Zero is known to be outside of IQFA |32j : 
in other words, Zero $ QLP|f (lqfa). Proposition 19.41 expands this result and shows that Zero is not even in 
QIPf(l?/o). 

Proposition 9.4 Zero QlPf (lqfa). 

Now, we begin with the proof of Proposition l9.4l Towards a contradiction, we first assume that a 1-iteration 
bounded QIP system (P, V) with lqfa verifier recognizes Zero with error probability < 1/2 — r\ for a certain 
constant 77 > 0. Let Q and V be respectively the set of V's inner states and the communication alphabet. Write 
E for our alphabet {0, 1} for simplicity. Without loss of generality, we assume henceforth that V does not query 
at the time when it enters a halting inner state; in particular, the time when the head is scanning the endmarker 
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First, we introduce the notions of "1-iteration condition" and "query weight." We fix an input x and let 
P' be any committed prover. For readability we use the notation Compy(P',x) to denote the computation of 
(P', V) on the input x. Moreover, PCompy(P',x) denotes the partial computation obtained by executing the 
QIP protocol (P',V) on any input whose prefix is x while the head is reading fyx (i.e., between the first step 
at (f; and the step at which the head reads the rightmost symbol of x and moves off x). When we consider a 
computation path, we understand that a computation path terminates either at a halting configuration or at a 
non-halting configuration £ of zero amplitude. 

For convenience, a committed prover P' is said to satisfy the 1-iteration condition at x with V if, for any 
query configuration £ of non-zero amplitude in Compy(P l ' ,x), no other query configuration exists between £ 
and the initial configuration in the computation. Let C^ v be the collection of all committed provers P' who 
satisfy the 1-iteration condition at x with V . ft is important to note that, whenever a prover in C x y answers 
to V with non-blank communication symbols with non-zero amplitude, V must change these symbols back to 
blank immediately since, otherwise, V is considered to make a second query Choose any prover P' in C^ v 
and consider the computation Compy{P' ,%)■ By introducing an extra projection, we modify Corrvpy{P' ,x) 
as follows. Whenever V conducts a measurement, we then apply a projection, mapping onto the Hilbert 
space span{|#)}, to the communication cell. This projection makes all non-blank symbols collapse. If the 
communication cell is blank, then V continues to the next step. Observe that this modified computation is 
independent of the choice of a committed prover. For this modified computation of V on x, we use the notation 
MCompv(x). Figure |21 illustrates the difference between a modified computation and two computations with 
different provers. The query weight wty (y) ofV at y conditional to x is the sum of all the squared magnitudes 
of the amplitudes of query configurations, in MCompy(xy), where V makes queries while reading y. For brevity, 
let wtv(y) — wty (y), where A is the empty string. By its definition, a query weight ranges between and 1 
and satisfies that tuty(x) + wty(y) = wty(xy) for any x, y € £*. 
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Figure 3: Example of a modified computation. The leftmost graph depicts the modified computation of V on 
input x. The latter two graphs are computations of V on x using different provers Pi and Pi- The black circles 
indicate query configurations whereas the white circles indicate non-query configurations. The dotted circle is 
the place where prover Pi forces V to generate a new computation path that destructively interferes with an 
existing path in the modified computation of V. 



Recall that (P, V) is 1-iteration bounded and recognizes Zero. The following lemma holds for the query 
weight of V. In the lemma, one round in a computation comprises the following series of executions: a prover 
first applies his strategy including the return of the blank symbol (if not the first round) and V then makes his 
move followed by a measurement. Note that the first round does not include a prover's move. In a modified 
computation, one round is similar but further includes an extra projection (described above) after V's own 
measurement. 

Lemma 9.5 Let P' be any committed prover and let x,y be any strings. 

1. Any committed prover satisfies the 1-iteration condition at x with V . 

2. Any query configuration £ of non-zero amplitude at round i in Compv{P',x) must appear at the same 
round i in MCompy(x) with the same amplitude for any i £ [1, \x\ + \\%. 

3. The query weight wty^ (y) is greater than or equal to the sum of all the squared magnitudes of amplitudes 
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of query configurations in PCompy(P' ,xy) while V's head is reading y. 

Proof. 1) Take any committed prover P' . In the case where x ^ Zero, since the QIP protocol (P',V) 
makes at most 1 iteration on x, P' clearly satisfies the 1-iteration condition at x with V . In contrast, assuming 
that x G Zero, consider the partial computation PCompy(P' ,x). Note that this partial computation is also a 
partial computation of (P', V) on xl. Since xl £ Zero, P' must satisfy the 1-iteration condition at xl with V. 
Therefore, P' satisfies the 1-iteration condition also at x. 

2) We prove the claim by induction on i 6 [1, |x| + l]g. The basis case i = 1 is trivially true since there is 
no prover's strategy. Consider the ith round. Let £ be any query configuration of non-zero amplitude occurring 
at round i in Compv{P' , x). Note from the first claim that every committed prover satisfies the 1-iteration 
condition at x with V. 

We first show that £ appears with non-zero amplitude at round i in MCompv{x). Assume otherwise that 
£ appears at round i in Compv(P ,x) but not in MCompy(x). This implies that, at a certain early round, 
as a response to a query configuration r/ in Compy(P',x) of non-zero amplitude, P' forces V to generate £ 
with non-zero amplitude later at the round i since, otherwise, V generates £ with no query and £ is therefore 
in MCompy(x), a contradiction. Since r] and £ are in the same computation path, this clearly violates the 1- 
iteration condition of P'. As a consequence, £ must appear with non-zero amplitude at round i in MCompy(x). 

Next, we show that £'s amplitude in CompyiP 1 , x) is the same as in MCompy(x). Towards a contradiction, 
we assume that the amplitudes of £ in Compy(P' ' ,x) and in MCompy(x) are different. Now, consider all 
computation paths that reach £. Note that, if such a path contains no query configuration (other than £), this 
path must appear in MCompy(x). There are two cases to discuss: either a new computation path leading to 
£ is added or an existing computation path to £ is annihilated. 

(Case 1) Consider any computation path 7 leading to £ in Compy(P' ,x) whose amplitude contributes to 
the difference of £'s amplitudes in Compy(P' ,x) and in MCompvix). Such a path 7 should not be present in 
MCompvix). The 1-iteration condition of P' implies that, since £'s amplitude is not 0, the path 7 cannot contain 
any query configuration of non-zero amplitude before reaching £. Hence, the path 7 must be in MCompy(x), 
a contradiction. 

(Case 2) The remaining case is that, at an early round, P' forces V to generate a number of computation paths 
that destructively interfere with an existing computation path 6 leading to £ in MCompvix). This interference 
annihilates the path 8, which causes the change of £'s amplitude in Compy(P' ,x). Figure [3] illustrates this 
case. We modify the strategy of P' by changing its amplitudes (but not the tape/communication symbols) so 
that 5 narrowly survives. Note that such a modification is possible because V moves exactly in the same way as 
before and therefore the modification does not incur any change of the computation Campy (P' ,x) except for 
the amplitude distribution. As a result, the path 6 connects two query configurations of non-zero amplitudes. 
This contradicts the first claim; namely, the 1-iteration condition of any committed prover. 

In either case, we reach a contradiction. Therefore, the claim holds. 

3) This follows directly from the second claim. □ 

We continue the proof of Proposition 19.41 Now, consider the value v defined as the supremum, over all 
strings w in Zero, of the query weight of V at w. Observe that < v < 1 by Lemma 19.51 We examine the two 
cases v = and v > separately. For readability, we omit the letter V whenever it is clear from the context. 

(Case 1: v = 0) Obviously, wt(w) — for all w € Zero. Toward a contradiction, it suffices to give a 
bounded-error lqfa that recognizes Zero since Zero £ 1QFA. Let Pi be the committed prover who applies only 
the identity operator at every step. The desired lqfa M behaves as follows. On input x, M simulates V on 
x with the "imaginary" prover Pj by maintaining the content of the communication cell as an integrated part 
of M's inner states. This is possible by defining M's inner state (q,a) to reflect both V's inner state q and a 
symbol a in the communication cell. Now, we claim that M recognizes Zero with bounded error. If input x 
is in Zero, then, since any communication with a prover has the zero amplitude, M correctly accepts x with 
probability > 1/2 + r;. Similarly, we can verify that, if x is not in Zero, M rejects x with probability > 1/2 + r\ 
because (Pi, V) must reject x with the same probability. Therefore, M recognizes Zero with error probability 
< l/2 — ?7, as requested. 

(Case 2: v > 0) Recall that the notation P w refers to the strategy of P on input w. Note that, for every 
real number 7 6 (0, v], there exists a string w in Zero such that wt(w) > v — 7. For each j £ E*, set 7^ = 
min{?7 2 /16(|?/| + l) 2 , v\ and choose the lexicographically minimal string w y S Zero such that wt(w y ) > v — j v . 

For each y G £*, define the new prover P' y that behaves on input w y yOT m for every m € N + in the following 
fashion: P' y takes the strategy P Wy yO while V's head is reading fyw y and then P' y behaves as Pi (i.e., applies 
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the identity operator) while V is reading the remaining portion y01 m $. For readability, we abbreviate w y y as 
y. We then claim the following. 

Claim. For any string y £ £*, p acc (yO,P y ) > 1/2 + jj/2. 

Proof of Claim. Let y be an arbitrary input string. Note that the protocol (P y , V) works in the same way 
as (Pyo,V) while V is reading fyw y . Consider wt^ Wy \yO). Note that wt(w y ) + wt^ w "\yQ) < v. It thus follows 
that w^ w "\yO) < 7j, using the inequality that wt(w y ) > v — j y . Lemma I9.5f 3) implies that, for any committed 
prover P*, wt^ Wy \yQ) bounds the sum of all the squared magnitudes of query configurations, while the head is 
reading yO, in the computation of (P* ,V) on the input w y yO. Therefore, a simple calculation (as in, e.g., [441 
Lemma 9]) shows that 

1/2 

\ Pacc (yO,P y ) ~Pacc(yO,Pyo)\ < 2 (urt^fc/O)) \y0\ < 2^{\y\ + 1) < 77/2. 

Since PacdyO, Py ) > 1/2 + 77, it follows that p acc (yO, P y ) > (1/2 + 77) - V /2 > 1/2 + V /2. □ 

Recall the set Q of inner states and the communication alphabet T. Set d = |<9||P| for brevity. Using 
Lemma f4. HI for each y £ S*, there exists a (|y0| + 2,d)-bounded QIP system (Py , V) that simulates (P^,V) 
on input 7/0. The initial superposition is |<?cb#j# d )j where we omit the qubits representing the head position 
of V because V is a lqfa verifier. Let V = span{|q) | g £ Q}, let = span{|er) | a 6 T}, and let P be 
the d-dimensional Hilbert space representing the prover's private tape. Let \ip y ) be the superposition in the 
global configuration space V <£> M. ® V obtained just after V's head moves off the right end of fyyO and Py 1 ** 
replies to V. For each number n £ N + , consider a (\y0\ + 2 + n, <i)-bounded QIP system (Py,™, where P a \ Tl 
simulates P' y while reading ^yO and applies the identity operator while reading 1™$. Noting that the prover P' y 

does nothing after V have read $w y , we can verify that (P y ,A, V) simulates (P y , V) on the input yOl". Letting 
/i = inf 2/e s*{|||V'y)||}, we consider the two subcases /i < rj/4 and /x > rj/4. 

(Subcase a: fi < n/4) There exists a string y such that /i < IHV'y)! < A 1 + Tf/4 < ij/2. This means that, 
after reading fyyO, the halting probability of V increases by no more than (r]/2) 2 . Consider the input yOl. Since 
Pacc{y®iPy 1] ) > 1/2+77/2, it follows that Pacc (yQl, Pj?}) > (l/2+?7/2)-|||V' y )|| 2 > 1/2. However, this contradicts 
our assumption that, for any committed prover P* , (P* , V) accepts yOl with probability < 1/2 — r\ < 1/2. 

(Subcase b: [i > i]/4) Let e be any sufficiently small positive real number and choose a string y such that 
II 1^)11 £ + e). The superposition of global configurations obtained after the operation of the protocol 
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{P y \ V) on yOV just before V scans $ becomes (PiE non Viy\ip y ), where Vb (b £ X) is the unitary operation of 
V when V is scanning the symbol b and Pj is the identity operation of a prover. For convenience, write W for 
PiE non Vi. For any integer j > 1, fi < WW^tpy)]] < fi + e. By a similar analysis in [35] (see also Lemma 
4.1.12]), there exist a constant c > independent of e and a number m £ N + such that || \ip y ) — W m \ip y )\\ < c-e 1 / 4 . 
From this inequality follows 

\ Pacc (yO,pW)- Pacc (yOi m ,pW)\ < IIW»>- W ro K)ll = lll^)-W m |^)|| <ce 1 / 4 , 

where the first inequality is obtained as in the proof of Lemma 16.31 We thus obtain the upper bound that 
\ P acc(yO,P y ) - P acc(y01 m ,P y )\ < ce l /\ Let e = (§) 4 . Since Pacc (yO,P y ) > 1/2 + 77/2, it follows that 
Pacc{y01 m , Py) > (1/2 + 77/2) - ce 1 / 4 = 1/2. This contradicts our assumption that (P*,V) accepts y01 m with 

probability < 1/2 — 77/2 < 1/2 for any committed prover P*. Therefore, Zero ^ QlPf (lqfa), as requested. 
This completes the proof of Proposition 

Since a lqfa verifier cannot remember the number of queries, we may not directly generalize the proof of 
Theorem IO to claim that QIP*(lg/o) ^ QIP* +1 (lqfa) for any constant k in N + . Nevertheless, we still 
conjecture that this claim holds. 

10 Future Directions 

There have been a surge of interests in QIP systems ^2112111201 ESI ESI partly because a QIP system embodies an 
essence of quantum computation and communication. Our research on weak-verifier QIP systems was inspired 
by the work of Dwork and Stockmeyer who extensively studied IP(2p/a) and AM(2p/a). Having started 
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with our basic qfa- verifier QIP systems, we have discussed several variants of restricted QIP systems and have 
demonstrated strengths and weaknesses of these QIP systems. Nonetheless, the theory of weak-verifier QIP 
systems is still vastly uncultivated. The development of new proof techniques is needed to settle down, for 
instance, all the pending questions left in this paper. We strongly hope that further research will unearth the 
crucial characteristics of the QIP systems. 

This final section discusses six important directions that lead to fruitful future research on weak-verifier QIP 
systems. 

• Modifying Verifier's Ability. Our verifier is a quantum finite automaton against a mighty prover who 
can apply any unitary operation. This paper has dealt with only three major qfa's: mo-lqfa's, lqfa's, and 
2qfa's. It is important to study the nature of quantum interactions between provers and different types of 
verifiers. There have been several variants of 2qfa's proposed in the literature. For instance, Amano and 
Iwama 3 studied so-called a 1.5qfa, which is a 2qfa whose head never moves to the left. Recently, Ambainis 
and Watrous considered a 2qfa whose head move is particularly classical. Instead of restricting the 
ability of qfa's, we can supplement an additional device to gain more computational power of qfa's. As 
an example, Golovkins lately studied a qfa that is equipped with a pushdown stack. Using these qfa 
models as verifiers, we need to conduct a comprehensive study on the corresponding QIP systems. 

• Curtailing Prover's Strategy. Another direction is to limit the prover's power. Instead of strengthening 
a verifier, for instance, we can restrict the size of the prover's strategy. Having already seen in Lemma l5.5l 
without diminishing the recognition power, we can limit the size of prover's private tape space to the size 
of the verifier's visible configuration space. If we further constrain the prover's strategy, how powerful is 
the corresponding QIP system? In the 1990s, Condon and Ladner ^5] studied IP systems with restricted 
provers who take only polynomial-size strategy. They showed that, with polynomial-size strategy, the 
IP systems with polynomial-time PTM verifiers exactly characterize Babai's class MA. Analogously, for 
instance, we can consider the QIP systems in which 2qfa verifiers play against (9(log log n)-space bounded 
provers. Such QIP systems still recognize certain non-regular languages. 

• Communicating through a Classical Channel. We may understand our QIP protocol as a 2-party 
communication protocol exchanging messages through a quantum channel. Recall that a classical prover 
performs only a unitary operation of entries either or 1. Seen as a communication protocol, we instead 
restrict a communication channel between two players, a prover and a verifier, to be classical. Such 
a communication may be realized by performing a measurement on the communication cell just before 
each player makes an access to the cell. The communication cell then becomes a probabilistic mixture of 
classical states. It is, nonetheless, unclear whether this QIP system is as powerful as our classical-prover 
QIP system. 

• Using Prior Entanglement. Quantum entanglement is of significant importance in quantum compu- 
tation and communication. The EPR pair^, for instance, is used to teleport a quantum state using a 
quantum correlation between two qubits. Consider the case where a verifier shares limited prior entan- 
glement with a prover in such a way that, before the start of a QIP protocol, a certain number of the 
verifier's inner states and a finite segment of the prover's private tape are entangled in a predetermined 
manner. This simple model of limited prior entanglement, nevertheless, does not enrich the computational 
resource of the QIP systems because, similar to the proof of QlP(lqfa) = REG, we can prove that the 
aforementioned limited prior entanglement makes the corresponding QIP systems recognize only regular 
languages. Therefore, other types of models arc needed to explore the usefulness of prior entanglement. 

• Playing against Multiple Provers. A natural extension of our basic QIP systems is obtained by 
providing each QIP system with multiple provers against a single verifier. In the polynomial-time setting, 
Kobayashi and Matsumoto 30 studied the QIP systems in which a uniform polynomial-size quantum- 
circuit verifier plays against multiple provers. These provers may further share prior entanglement among 
them (but not with a verifier). Multiple-prover QIP systems of Kobayashi and Matsumoto are shown 
to characterize the complexity class NEXP [20]. In a classical case, Feige and Shamir JH] constructed 
a 2-prover IP system with a 2pfa verifier (using the model of Dwork and Stockmeyer) for each recursive 
language. Naturally, we expect the multiple-prover QIP systems with qfa verifiers to demonstrate a similar 

increase in power over the singic-provc r QIP systems. 

t^The EPR pair is the 2-qubit quantum state |<t> + } = ( 1 00) + [ll))/v2, which was proposed by Einstein, Podolsky, and Rosen in 
1935. 
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• Making Knowledge-Based Interactions. Lately, a great attention has been paid to a quantum zero- 
knowledge proof systems (QZKP systems, in short) |29l I41j . As a followup to their 2pfa- verifier IP 
systems, Dwork and Stockmcycr also studied zero-knowledge proof systems played between provers and 
2pfa verifiers ^Hj- It is desirable to develop a theory of QZKP systems with qfa verifiers in connection to 
quantum cryptography. 

Acknowledgment. The first author is grateful to Hirotada Kobayashi for a detailed presentation of his result. 
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